Smart Search Assistant: AI Partner Check
jlbpahgopcmomkgegpbmopfodolajhbl
Risk Score
3.13
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Broad host access (https://*/*) with content scripts on every page — high exfil surface.
- AI extension calling api.smartsearcher.net processes page content; no CSP limiting outbound.
- Developer email is free-webmail (gmail) with no developer name, reducing accountability.
- Privacy policy admits third-party sharing but lacks data retention disclosure.
- innerHTML DOM-XSS sink in content.js without CSP protection amplifies XSS risk.
Evidence
- broad_host_access manifest host_permissions and content_scripts_matches both set to https://*/*; runs on every HTTPS site.
- ai_extension_page_content manifest Category AI with content scripts on all pages posting to api.smartsearcher.net.
- free_webmail_developer store Developer email charloesbharthwers@gmail.com; no developer name listed; gmail domain.
- no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit extension-level CSP.
- privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- dom_xss_sink crx js/content.js assigns innerHTML from variable without sanitization; no CSP mitigates.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partial trust discount applied.
- manifest_name_localized manifest manifest_name=__MSG_name__ and manifest_description=__MSG_desc__; localized strings only.
Permissions Breakdown
- storage low Stores local extension state; minimal risk on its own.
- https://*/* high Broad host access across all HTTPS sites; content scripts inject into every page.
- content_scripts_matches: https://*/* high Content scripts run on every HTTPS page, giving broad DOM read/write access.
Pillar Scores
Permissions5.50
Reputation5.50
Network2.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:54
Listing SHA
dd9f1374570d…
Force block
— not fired
Score recovered
no
Elapsed
—