Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Export Gemini Chats to PDF - Download & Archive Gemini Chats

mmgbhlbbnlpcndmhgnghhembmincbibd
Risk Score
5.24
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 337
Rating 4.4
Last updated 2026-08-29
Manifest version MV3
CSP present ✅ yes
Developer neocrtxai@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Gemini brand impersonation by unverified gmail developer with no stated org affiliation.
  • Privacy policy is 481 chars, not scoped to this extension, and silent on data collection — scored as near-absent.
  • 8 innerHTML DOM-XSS sinks across content/popup/options scripts processing AI chat HTML; CSP connect-src is wildcard.
  • Developer backend API (Cloud Run) plus Yandex OAuth integrations create unexpected exfiltration surfaces for chat data.
  • install_url_hijack flagged; JS external hosts include buy.stripe.com, x.com, grok.com beyond stated Gemini scope.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'gemini'; developer domain is gmail.com, confirmed_owner=false.
  • privacy_policy_inadequate api Policy fetched but length=481, scope_extension=false, data_collection=false; third_party_silence=true → +9.0 privacy.
  • dom_xss_sinks crx 8 dom_sink_innerhtml_userctrl findings across content, popup, options, utils, lib files processing AI chat HTML.
  • connect_src_wildcard manifest CSP connect-src is '* data: blob: filesystem:' — effectively unrestricted outbound connections.
  • unexpected_external_hosts crx js_external_hosts include buy.stripe.com, x.com, grok.com, chat.deepseek.com, cocounsel.thomsonreuters.com — scope mismatch.
  • install_url_hijack manifest install_url_hijack=true; extension opens a URL on install.
  • free_webmail_dev_no_name store Developer email neocrtxai@gmail.com, developer_name empty, no verified publisher badge.
  • yandex_oauth_integration manifest Host permissions include oauth.yandex.com and oauth.yandex.ru — unusual for a Gemini PDF exporter.

Permissions Breakdown

  • storage low Standard local state persistence; low risk.
  • downloads medium Can trigger file downloads to user machine; matches PDF export claim.
  • downloads.open medium Can auto-open downloaded files; slight escalation beyond downloads alone.
  • identity medium OAuth token access; used here for cloud integrations (Dropbox, Notion, Yandex).
  • activeTab low Transient page access on user click; narrow scope.
  • https://*.amazonaws.com/* medium Broad AWS access; could reach any S3 bucket or API hosted on AWS.
  • https://*.google.com/* medium Covers all Google subdomains including accounts; needed for Gemini but overbroad.
  • https://*.googleusercontent.com/* medium User content CDN; required for Gemini chat image assets.
  • https://ai-chat-exporter-api-gemini-*.run.app/* medium Developer-controlled backend API; chat data may be transmitted here.
  • https://aistudio.google.com/* low Google AI Studio; plausibly related to Gemini export function.
  • https://api.dropboxapi.com/* medium Full Dropbox API access; cloud storage integration feature.
  • https://api.notion.com/* medium Notion API access; cloud storage integration feature.
  • https://cloud-api.yandex.net/* medium Yandex cloud API; unexpected for a Gemini-to-PDF tool targeting Western users.
  • https://content.dropboxapi.com/* medium Dropbox content endpoint; used for file uploads.
  • https://gemini.google.com/* medium Primary target; content scripts run here to extract chat data.
  • https://oauth.yandex.com/* medium Yandex OAuth; unusual integration for a Gemini PDF exporter.
  • https://oauth.yandex.ru/* medium Yandex OAuth Russian domain; same concern as yandex.com OAuth.
  • https://www.googleapis.com/* medium Broad Google APIs access; needed for Drive/Docs integrations.

Pillar Scores

Permissions4.30
Reputation7.50
Network5.50
Webstore6.50
Maintenance0.00
Privacy9.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 13:52
Listing SHA 0da85a35bcce…
Force block — not fired
Score recovered no
Elapsed