Gemini Chat Sidebar
hcclofdokohcpnenkiamgnageeaclfce
Risk Score
5.84
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; collects and shares data with third parties.
- desktopCapture + scripting + <all_urls> gives broad screen and page access on every site visited.
- No CSP present (MV3); three innerHTML sinks across content/sidebar scripts elevate DOM-XSS risk.
- Developer identity is minimal (single name 'Garcia', custom .vip domain, unverified publisher).
- AI extension processes page content on all URLs with screen capture capability — high exfil surface.
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; data_collection+third_party_sharing=true.
- desktopCapture_permission manifest desktopCapture declared alongside scripting and <all_urls> — allows screen capture on any page.
- no_csp crx content_security_policy is null; no CSP protection for MV3 extension with DOM sinks.
- dom_xss_sinks crx Three files contain innerHTML assignments from variables with no CSP guard — DOM-XSS risk.
- unverified_publisher store verified_publisher=false, is_featured_by_google=false; developer is 'Garcia' at igemini.vip.
- ai_page_content_access manifest AI category extension with content_scripts on <all_urls> and desktopCapture — broad data access.
- ko_fi_external_host crx js_external_hosts includes ko-fi.com and storage.ko-fi.com — donation/monetization widget bundled.
- brand_mention_confirmed_owner store brand_mention.is_impersonation=false, confirmed_owner=true for 'gemini' brand reference.
Permissions Breakdown
- storage low Standard key-value storage, low risk.
- unlimitedStorage low Allows large storage quota; minor risk.
- sidePanel low Opens a side panel UI; low direct risk.
- activeTab medium Grants access to the current tab on activation.
- scripting high Allows programmatic JS injection into pages.
- downloads medium Can initiate and manage file downloads.
- desktopCapture high Can capture screen content — significant privacy risk.
- <all_urls> (host) high Content scripts run on every page; broad reach amplifies scripting risk.
Pillar Scores
Permissions7.50
Reputation5.50
Network4.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
b266cb09c5e7…
Force block
— not fired
Score recovered
no
Elapsed
27.5s