Claudify - The Ultimate Toolbox for Claude.ai
hofibnjfkkmlhnpjegcekcnnpnpjkgdj
Risk Score
5.62
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension, collects data, shares with third parties (score +10).
- Brand impersonation: extension targets Claude.ai without being affiliated with Anthropic; is_impersonation=true.
- Gmail developer with no developer name and no business domain — unaccountable actor.
- install_url_hijack: onInstalled opens chrome://extensions/shortcuts — unusual forced redirect on install.
- Two innerHTML DOM-XSS sinks with no CSP present, enabling potential XSS on claude.ai sessions.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands=['claude'], confirmed_owner=false, dev domain=gmail.com.
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_dev_no_name manifest developer_email=vinodsliyanage@gmail.com, developer_name empty, no business website.
- install_url_hijack crx install_url_hijack=true, target=chrome://extensions/shortcuts — opens page on install.
- dom_xss_sinks_no_csp crx 2x dom_sink_innerhtml_userctrl in ui.js and pdf-printer.js; csp_present=false raises XSS risk.
- description_mismatch store Description promises download functionality but no 'downloads' permission declared.
- verified_publisher_flag store verified_publisher=true but developer domain is gmail.com — cap at -1.0 per v3.5 rule 0c.
- js_external_hosts crx External JS hosts: claude.ai, github.com, reactjs.org — 2 countries (IN, US).
Permissions Breakdown
- storage low Local data persistence; minimal risk alone.
- scripting high Allows programmatic script injection into pages; high capability risk.
- commands low Keyboard shortcut registration; low standalone risk.
- tabs medium Can read URLs and titles of open tabs across sessions.
- https://claude.ai/chat/* medium Host permission scoped to claude.ai only; narrow but targets AI conversation data.
Pillar Scores
Permissions3.30
Reputation7.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
cd427841b5b6…
Force block
— not fired
Score recovered
no
Elapsed
26.2s