AI Exporter: Save ChatGPT, Gemini to PDF, Word, MD and Notion
kagjkiiecagemklhmhkabbalfpbianbe
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true — admits broad data sharing without scoping to this extension (Privacy +10.0)
- brand_mention.is_impersonation=true (ChatGPT/Gemini) with gmail dev email and no verified business identity (Reputation +2.0)
- Broad host_permissions *://*/* on an AI content-scraping extension with cookies permission — can read/exfil any site session
- CSP sandbox allows unsafe-eval and unsafe-inline on script-src; DOM-XSS sink (innerHTML) found in bundled JS
- Uninstall URL hijack detected (uninstall_url_hijack=true) and developer is free-webmail gmail with no developer name
Evidence
- privacy_policy_admits_third_party_sharing_without_scope api Policy fetched from saveai.net/privacy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0 (D rule)
- brand_impersonation_gmail_dev store brand_mention.is_impersonation=true (chatgpt,gemini); developer is mrsoniceman@gmail.com with no developer name; verified_publisher=true
- cookies_plus_all_urls manifest cookies permission + *://*/* host_permissions; ×1.2 amplifier applied — can read any site session cookie
- csp_unsafe_eval_unsafe_inline crx sandbox CSP contains unsafe-eval and unsafe-inline on script-src; dom_sink_innerhtml_userctrl in code_findings_raw → Code +2.0
- uninstall_url_hijack crx uninstall_url_hijack=true; monetization/tracking behavior on uninstall redirecting to 3rd party
- monetization_hits_google_analytics api threat_intel.monetization_hits=[google-analytics.com]; category=AI (not Adblock/Shopping) → Webstore +1.0 telemetry tier
- ai_extension_processing_page_content store AI/GenAI extension with content_scripts on 20 AI platform origins including chatgpt.com, gemini.google.com → Webstore +2.5
- free_webmail_no_developer_name store developer_email=mrsoniceman@gmail.com, developer_name=''; free webmail + no business name raises accountability risk
Permissions Breakdown
- tabs medium Can enumerate open tabs and their URLs; moderate risk for content exfil.
- storage low Local data persistence; low standalone risk.
- cookies high Can read/write cookies across origins; paired with *://*/* enables session theft.
- contextMenus low UI affordance only; low risk.
- declarativeNetRequest medium Can modify/block network requests declaratively; moderate risk without webRequest.
- sidePanel low UI surface only; low standalone risk.
- *://*/* high Broad host access on all URLs; combined with cookies enables cross-site data access.
Pillar Scores
Permissions7.00
Reputation6.50
Network4.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
d380766f7c98…
Force block
— not fired
Score recovered
no
Elapsed
28.9s