Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Claudify - The Ultimate Toolbox for Claude.ai

hofibnjfkkmlhnpjegcekcnnpnpjkgdj
Risk Score
5.62
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 2,000
Rating 4.2
Last updated 2026-05-13 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer vinodsliyanage@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension, collects data, shares with third parties (score +10).
  • Brand impersonation: extension targets Claude.ai without being affiliated with Anthropic; is_impersonation=true.
  • Gmail developer with no developer name and no business domain — unaccountable actor.
  • install_url_hijack: onInstalled opens chrome://extensions/shortcuts — unusual forced redirect on install.
  • Two innerHTML DOM-XSS sinks with no CSP present, enabling potential XSS on claude.ai sessions.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands=['claude'], confirmed_owner=false, dev domain=gmail.com.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_dev_no_name manifest developer_email=vinodsliyanage@gmail.com, developer_name empty, no business website.
  • install_url_hijack crx install_url_hijack=true, target=chrome://extensions/shortcuts — opens page on install.
  • dom_xss_sinks_no_csp crx 2x dom_sink_innerhtml_userctrl in ui.js and pdf-printer.js; csp_present=false raises XSS risk.
  • description_mismatch store Description promises download functionality but no 'downloads' permission declared.
  • verified_publisher_flag store verified_publisher=true but developer domain is gmail.com — cap at -1.0 per v3.5 rule 0c.
  • js_external_hosts crx External JS hosts: claude.ai, github.com, reactjs.org — 2 countries (IN, US).

Permissions Breakdown

  • storage low Local data persistence; minimal risk alone.
  • scripting high Allows programmatic script injection into pages; high capability risk.
  • commands low Keyboard shortcut registration; low standalone risk.
  • tabs medium Can read URLs and titles of open tabs across sessions.
  • https://claude.ai/chat/* medium Host permission scoped to claude.ai only; narrow but targets AI conversation data.

Pillar Scores

Permissions3.30
Reputation7.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA cd427841b5b6…
Force block — not fired
Score recovered no
Elapsed 26.2s