Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Export Google AI Studio Chats to PDF - Download Google AI Studio Chats

lhgbhgflgoedbhlfbghcikonigcgiibo
Risk Score
5.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 538
Rating 4.7
Last updated 2026-08-29
Manifest version MV3
CSP present ✅ yes
Developer neocrtxai@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Google brand impersonation by free-webmail dev with no verified publisher status
  • Privacy policy fetched but out-of-scope (481 chars, no extension-specific data collection disclosure)
  • Install-URL hijack opens third-party page on installation; potential tracking/redirect
  • CSP connect-src is unrestricted ('*') allowing data exfiltration to arbitrary endpoints
  • 8 innerHTML DOM-XSS sinks across content/popup/options files processing AI chat HTML

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer is gmail.com, not Google; no verified_publisher.
  • install_url_hijack manifest install_url_hijack=true; onInstalled opens third-party URL — potential tracking redirect.
  • csp_connect_src_wildcard crx connect-src * data: blob: filesystem: — unrestricted outbound connections despite MV3.
  • free_webmail_dev_no_name store developer_email=neocrtxai@gmail.com; developer_name empty; no verified publisher.
  • privacy_policy_inadequate api Policy fetched (481 chars), scope_extension=false, data_collection=false; generic non-scoped stub.
  • dom_xss_sinks crx 8 innerHTML-from-variable findings across content, popup, options, lib files.
  • search_engine_count_3 crx Extension contacts google.com, yandex.com, yandex.ru — three search engines; monetization concern.
  • broad_host_permissions manifest 13 host_permissions including *.google.com, *.amazonaws.com, Yandex OAuth, Dropbox, Notion APIs.

Permissions Breakdown

  • storage low Stores local settings; low risk in isolation.
  • downloads medium Allows saving files to disk; expected for PDF export but broadens attack surface.
  • downloads.open medium Can open downloaded files; slight elevation above plain downloads.
  • identity medium Access to OAuth tokens; used for Dropbox/Notion/Yandex sign-in but can leak credentials.
  • activeTab low Scoped to active tab on user gesture; lower risk than broad host access.
  • host: https://*.amazonaws.com/* medium Broad AWS host access; cloud storage upload path but wider than needed.
  • host: https://*.google.com/* medium Covers all Google subdomains including sensitive services beyond aistudio.
  • host: https://*.googleusercontent.com/* medium Covers user content; potential access to authenticated resources.
  • host: https://ai-chat-exporter-api-...run.app/* medium Developer-operated backend API; chat content may transit this server.
  • host: https://aistudio.google.com/* medium Primary target; content script reads AI Studio chats.
  • host: https://api.dropboxapi.com/* medium Dropbox API access; allows upload of exported content to third-party cloud.
  • host: https://api.notion.com/* medium Notion API; same third-party cloud upload concern.
  • host: https://cloud-api.yandex.net/* medium Yandex cloud API; Russian-hosted service, data sovereignty concern.
  • host: https://content.dropboxapi.com/* medium Dropbox content endpoint for file transfers.
  • host: https://gemini.google.com/* medium Covers Gemini UI; extends reach beyond stated AI Studio scope.
  • host: https://oauth.yandex.com/* medium Yandex OAuth; handles auth tokens for Russian cloud service.
  • host: https://oauth.yandex.ru/* medium Duplicate Yandex OAuth on .ru TLD.
  • host: https://www.googleapis.com/* medium Broad Google API access; enables Drive, Sheets, and other sensitive APIs.

Pillar Scores

Permissions3.80
Reputation7.50
Network5.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 13:30
Listing SHA 24ea6f21aa25…
Force block — not fired
Score recovered no
Elapsed