Export Google AI Studio Chats to PDF - Download Google AI Studio Chats
lhgbhgflgoedbhlfbghcikonigcgiibo
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Google brand impersonation by free-webmail dev with no verified publisher status
- Privacy policy fetched but out-of-scope (481 chars, no extension-specific data collection disclosure)
- Install-URL hijack opens third-party page on installation; potential tracking/redirect
- CSP connect-src is unrestricted ('*') allowing data exfiltration to arbitrary endpoints
- 8 innerHTML DOM-XSS sinks across content/popup/options files processing AI chat HTML
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; developer is gmail.com, not Google; no verified_publisher.
- install_url_hijack manifest install_url_hijack=true; onInstalled opens third-party URL — potential tracking redirect.
- csp_connect_src_wildcard crx connect-src * data: blob: filesystem: — unrestricted outbound connections despite MV3.
- free_webmail_dev_no_name store developer_email=neocrtxai@gmail.com; developer_name empty; no verified publisher.
- privacy_policy_inadequate api Policy fetched (481 chars), scope_extension=false, data_collection=false; generic non-scoped stub.
- dom_xss_sinks crx 8 innerHTML-from-variable findings across content, popup, options, lib files.
- search_engine_count_3 crx Extension contacts google.com, yandex.com, yandex.ru — three search engines; monetization concern.
- broad_host_permissions manifest 13 host_permissions including *.google.com, *.amazonaws.com, Yandex OAuth, Dropbox, Notion APIs.
Permissions Breakdown
- storage low Stores local settings; low risk in isolation.
- downloads medium Allows saving files to disk; expected for PDF export but broadens attack surface.
- downloads.open medium Can open downloaded files; slight elevation above plain downloads.
- identity medium Access to OAuth tokens; used for Dropbox/Notion/Yandex sign-in but can leak credentials.
- activeTab low Scoped to active tab on user gesture; lower risk than broad host access.
- host: https://*.amazonaws.com/* medium Broad AWS host access; cloud storage upload path but wider than needed.
- host: https://*.google.com/* medium Covers all Google subdomains including sensitive services beyond aistudio.
- host: https://*.googleusercontent.com/* medium Covers user content; potential access to authenticated resources.
- host: https://ai-chat-exporter-api-...run.app/* medium Developer-operated backend API; chat content may transit this server.
- host: https://aistudio.google.com/* medium Primary target; content script reads AI Studio chats.
- host: https://api.dropboxapi.com/* medium Dropbox API access; allows upload of exported content to third-party cloud.
- host: https://api.notion.com/* medium Notion API; same third-party cloud upload concern.
- host: https://cloud-api.yandex.net/* medium Yandex cloud API; Russian-hosted service, data sovereignty concern.
- host: https://content.dropboxapi.com/* medium Dropbox content endpoint for file transfers.
- host: https://gemini.google.com/* medium Covers Gemini UI; extends reach beyond stated AI Studio scope.
- host: https://oauth.yandex.com/* medium Yandex OAuth; handles auth tokens for Russian cloud service.
- host: https://oauth.yandex.ru/* medium Duplicate Yandex OAuth on .ru TLD.
- host: https://www.googleapis.com/* medium Broad Google API access; enables Drive, Sheets, and other sensitive APIs.
Pillar Scores
Permissions3.80
Reputation7.50
Network5.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 13:30
Listing SHA
24ea6f21aa25…
Force block
— not fired
Score recovered
no
Elapsed
—