ChatGPT Assistant - Use AI Everywhere
kldepdcdedfibmjnggmolhffdddbphjg
Risk Score
7.05
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Privacy policy on unrelated domain (trackandtrace.tools) admits data collection + 3rd-party sharing with no extension-specific scope — worst-case privacy posture.
- Extension abandoned 39 months; react@0.9.0 CVE (XSS, high) in active content-script with no CSP to mitigate exploitation.
- Brand impersonation: uses 'ChatGPT' name without being OpenAI-verified; confirmed by brand_mention.is_impersonation.
- Install-URL hijack opens chat.openai.com on install; uninstall-URL hijack sends to Google Forms survey — both are manipulation signals.
- Multiple innerHTML + new Function() findings across content-scripts injected on all major search engines with no CSP; code quality score >=6 triggers block.
Evidence
- privacy_policy_scope_mismatch store Policy URL is trackandtrace.tools — unrelated domain; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
- brand_impersonation store brand_mention.is_impersonation=true for 'chatgpt'; developer not verified owner; not verified_publisher for impersonation discount.
- install_url_hijack crx onInstalled opens https://chat.openai.com/chat (+2.0 webstore).
- uninstall_url_hijack crx setUninstallURL to Google Forms survey (+3.0 webstore).
- stale_extension store 39 months since update; MV3 but react@0.9.0 (CVE high) bundled; maintenance pillar=10.0.
- cve_react_xss crx react@0.9.0 in content-script.3da2ae17.js; high-severity XSS, fixed_in 0.14.0; no CSP → CVE amplifier ×1.5.
- code_quality_innerHTML_function_constructor crx 13 dom_sink_innerhtml_userctrl + 3 function_constructor findings across content-scripts; no CSP → elevated code quality score.
- no_csp crx content_security_policy=null on MV3; dom_sink + CVE present → v2 FIX B and CVE amplifier both apply.
CVE Exposures (1)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| react@0.9.0 | react@0.9.0 | high | 0.14.0 | Cross-Site Scripting in react |
Permissions Breakdown
- alarms low Schedules background tasks; minimal data exposure.
- activeTab low Temporary access to current tab on user action; scoped.
- storage low Local preference storage; no cross-site risk alone.
- tabs medium Can read tab URLs and titles; moderate info disclosure.
- contextMenus low Adds right-click menu items; low risk.
- content_scripts: https://*.google.com/* etc. medium Scripts injected on 8 origins including all Google/Bing/DDG searches.
Pillar Scores
Permissions2.90
Reputation7.00
Network2.00
Webstore7.00
Maintenance10.00
Privacy10.00
Code Quality7.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA
a0b5ab43a73f…
Force block
— not fired
Score recovered
no
Elapsed
34.1s