Folders for Gemini
moolbfcgjpllmjemlgajopefhbekieag
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gemini brand impersonation: dev is gmail user with no verified ownership of 'Gemini' branding.
- Privacy policy is Google's generic account policy — does not scope data handling to this extension.
- Uninstall URL hijack redirects to forms.gle (third-party feedback form) on removal.
- No CSP on MV3 extension with innerHTML DOM-XSS sink in content script on gemini.google.com.
- Free-webmail developer (gmail) with no business domain — low accountability, easy to sell/transfer.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['gemini'], confirmed_owner=false, dev domain=gmail.com
- generic_privacy_policy store Policy is Google account policy (460KB); scope_extension=false, data_collection=true, third_party_sharing=true
- uninstall_url_hijack crx uninstall_url_target=https://forms.gle/tspEfzjCVxRVFv4MA — redirects to 3rd-party form on uninstall
- dom_xss_sink crx content.js: svg.innerHTML=pathData — uncontrolled DOM-XSS sink, no CSP present
- free_webmail_dev store Developer email ramongallinadcorti@gmail.com; no business website; low accountability
- is_featured_by_google store Extension carries Google Featured badge — partial trust signal despite other risks
- no_csp crx content_security_policy=null on MV3 extension; no mitigation for innerHTML XSS sink
- cve_findings crx cve_findings_raw=[]; no CVEs detected in bundled libraries
Permissions Breakdown
- storage low Stores folder/chat organization data locally. Low risk.
- https://gemini.google.com/* medium Host permission scoped to Gemini only; matches stated function but enables content-script DOM access.
Pillar Scores
Permissions1.30
Reputation7.50
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
384772c1c851…
Force block
— not fired
Score recovered
no
Elapsed
22.7s