Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Chat AI for Chrome

jhhjbaicgmecddbaobeobkikgmfffaeg
Risk Score
4.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 3,000
Rating
Last updated 2026-04-23 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer nicholascopeland241@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search provider override routes all searches to developer-controlled chataiforchrome.com — classic monetization shell.
  • Free-webmail Gmail developer, no developer name listed, no verified publisher badge — unverifiable identity.
  • Uninstall URL hijack confirmed; install URL hijack opens developer site on install — aggressive user-funnel manipulation.
  • Cookies permission paired with search override creates capability to correlate search queries with session identity.
  • Low install count (3,000) with HIGH-tier permissions and monetization shape suggests tail-attack or early-stage monetization shell.

Evidence

  • search_provider_override_default manifest chrome_settings_overrides.search_provider.is_default=true; routes searches to chataiforchrome.com/auto-suggest/search.php
  • uninstall_url_hijack crx uninstall_url_hijack=true; aggressive retention/tracking on uninstall.
  • install_url_hijack crx install_url_hijack=true; target=https://chataiforchrome.com/extension-success/
  • free_webmail_no_dev_name store developer_email=nicholascopeland241@gmail.com; developer_name empty; no verified publisher.
  • cookies_permission manifest cookies declared alongside search-override; can correlate search queries with session cookies.
  • privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — fully disclosed.
  • low_installs_high_perm store 3,000 installs with search-provider override + cookies; monetization shell fingerprint.
  • no_cve_no_bad_hosts api cve_findings_raw=[], bad_host_hits=[], monetization_hits=[] — no direct threat-intel hits.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • cookies high Can read/write cookies; scoped to chataiforchrome.com host only but still HIGH-tier.
  • chrome_settings_overrides.search_provider (is_default=true) high Silently replaces default search engine with developer-controlled endpoint.

Pillar Scores

Permissions6.00
Reputation8.00
Network0.00
Webstore8.00
Maintenance1.50
Privacy0.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:45
Listing SHA b15bf12a4739…
Force block — not fired
Score recovered no
Elapsed