Grok AI
hafhkoalnlpoifpidohfjlmeemfifndi
Risk Score
5.30
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail dev (joldeveloply@gmail.com) with no developer name — unverifiable operator identity impersonating 'Grok AI' brand.
- Privacy policy is Google's generic account policy — no scope to this extension; policy admits data collection and 3rd-party sharing.
- Uninstall and install URL hijacks declared — classic traffic-monetization shell pattern.
- 6 external JS hosts on easytool.dev subdomain (chatgpt-5, deepseek-ai, gemini-2, grok-3, grok-ai, perplexity-ai) loaded remotely — supply-chain risk.
- No CSP and DOM-XSS innerHTML sink in iframe-service JS — remote JS hosts can inject arbitrary content.
Evidence
- free_webmail_dev_no_name store Developer email joldeveloply@gmail.com; developer_name is empty. No verifiable business identity.
- install_uninstall_url_hijack crx Both uninstall_url_hijack and install_url_hijack are true — monetization shell fingerprint.
- external_js_hosts crx 6 easytool.dev subdomains loaded as external JS: chatgpt-5, deepseek-ai, gemini-2, grok-3, grok-ai, perplexity-ai.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; collects+shares data.
- no_csp_dom_xss_sink crx csp_present=false AND dom_sink_innerhtml_userctrl in iframe-service-D2VojyOp.js — XSS risk amplified.
- is_featured_by_google store Extension carries Google Featured badge, partially offsetting reputation concern.
- ai_extension_multi_provider_hosts crx Extension hosts content from 6 AI-brand subdomains under single easytool.dev operator — aggregator shell pattern.
- manifest_localized_name_desc crx manifest_name=__MSG_appName__ and manifest_description=__MSG_shortDesc__ — store name relies entirely on locale strings.
Permissions Breakdown
- storage low Local key-value storage only; no cross-origin data exfil by itself.
- sidePanel low Opens a side panel UI; no sensitive data access on its own.
Pillar Scores
Permissions0.60
Reputation8.00
Network3.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:42
Listing SHA
50f3b4c46a5a…
Force block
— not fired
Score recovered
no
Elapsed
—