Claude Limit & Usage Tracker - ClaudeKarma
hoffoefgnaakaafdfjpnjdkclhjkebjn
Risk Score
3.23
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: 'claude' brand mentioned in name/description; dev is not Anthropic and not verified owner.
- Uninstall URL hijack flag set (target unknown); install URL hijack also flagged — destination unverified.
- Developer identity weak: no dev name, duck.com privacy-relay email, no verified business domain.
- Privacy policy scoped to extension but discloses third-party sharing without specifying recipients or data retained.
- 8 external JS hosts referenced (tokenkarma.app, twitter, github, linkedin, mozilla, youtube) — surface wider than stated function.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'claude'; confirmed_owner=false; developer is not Anthropic.
- install_uninstall_url_hijack crx install_url_hijack=true AND uninstall_url_hijack=true; targets are null — destination unverifiable.
- developer_identity store developer_name empty; email tabkarma@duck.com is a privacy-relay address; no verified business.
- verified_publisher store verified_publisher=true; provides -1.0 reputation discount (not full -3.0 due to impersonation context).
- privacy_policy_third_party api Policy fetched, scoped, no data_collection, but third_party_sharing=true and retention=false.
- external_hosts crx 8 external JS hosts: claude.ai, tokenkarma.app, static.tokenkarma.app, github, twitter, linkedin, mozilla, youtube.
- host_permission_scope manifest host_permissions limited to https://claude.ai/*; content_scripts match same origin — appropriately narrow.
- cve_and_code_clean crx cve_findings_raw empty; code_findings_raw empty; obfuscation_score=0.0; MV3 with strict CSP.
Permissions Breakdown
- storage low Stores local usage tracking data; no remote exfil observed.
- alarms low Used for periodic limit-check scheduling; low impact.
- notifications low Alerts user on limit events; no cross-site risk.
- https://claude.ai/* medium Host permission scoped to claude.ai only; matches stated function but enables content reads.
Pillar Scores
Permissions1.60
Reputation6.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
ea0a961bf2b5…
Force block
— not fired
Score recovered
no
Elapsed
20.8s