AI Toolbox: Folders, Prompts, Advanced Search & Export for AI Chats
jlalnhjkfiogoeonamcnngdndjbneina
Risk Score
2.93
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- webRequest permission enables observation of all ChatGPT network traffic including auth tokens.
- uninstall_url_hijack detected — extension calls setUninstallURL to a third-party target.
- JS external hosts include media.happyhourhub.co, twitter.com, x.com — unrelated to stated AI-chat function.
- No CSP defined (MV3 default applies) but DOM-XSS innerHTML sink found in xsearch.js.
- AI extension with scripting + webRequest on chatgpt.com processes sensitive conversation content.
Evidence
- uninstall_url_hijack manifest uninstall_url_hijack=true; target null but setUninstallURL call to 3rd party detected — webstore +3.0.
- external_hosts_scope_mismatch crx js_external_hosts includes media.happyhourhub.co, twitter.com, x.com — unrelated to AI-chat function.
- dom_xss_sink crx innerHTML assigned from variable in xsearch.js; no CSP present, triggering +2.0 code-quality per FIX B.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied, floored at 2.0.
- privacy_policy_adequate api Policy fetched, scoped, data_collection=true, retention=true, third_party_sharing=true; privacy pillar 0.0.
- webRequest_on_chatgpt manifest webRequest + scripting scoped to chatgpt.com; can observe auth tokens and conversation payloads.
- ai_extension_page_content store AI category extension with content_scripts on chatgpt.com processing sensitive user chat data.
- host_geo_diversity api 3 countries (CA, DE, US); below threshold of 4 for geo-diversity penalty.
Permissions Breakdown
- storage low Stores local extension data; expected for a productivity tool.
- webRequest high Can observe network requests on declared hosts; broad capability even scoped.
- activeTab medium Grants temporary access to the active tab; limited scope.
- alarms low Schedules background tasks; low risk in isolation.
- scripting medium Allows programmatic script injection into tabs; elevated but scoped to chatgpt.com.
- host: https://chatgpt.com/* medium Scoped to ChatGPT; matches stated AI-chat-management function.
- host: https://api.infi-dev.com/ai-toolbox/* low Developer's own API endpoint; expected for sync/auth.
Pillar Scores
Permissions4.50
Reputation2.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:47
Listing SHA
84af9f86e429…
Force block
— not fired
Score recovered
no
Elapsed
—