Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Wilds AI: Universal AI Chat & Story Exporter

nblmojeghhciehfmjondiechgchfdfea
Risk Score
3.54
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 47
Rating
Last updated 2026-06-10 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer team@wilds.ai
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own account policy — not scoped to this extension at all, admits data collection and 3rd-party sharing.
  • Content scripts on ChatGPT, Claude, Gemini, and multiple AI chat platforms can silently read all user conversation content.
  • No CSP declared (MV3 default applies) combined with innerHTML DOM-XSS sink in popup script.
  • Developer name absent; only 47 installs — very low adoption makes vetting hard and increases tail-attack-surface concern.
  • js_external_hosts include hertzen.com (html2canvas CDN) and reactjs.org — third-party JS origin references in a low-install extension.

Evidence

  • privacy_policy_generic_google store Privacy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case privacy disclosure.
  • content_scripts_ai_platforms manifest Content scripts declared on ChatGPT, Claude, Gemini, Character.AI, JanitorAI, Chai, AIDungeon — broad AI conversation access.
  • dom_xss_sink crx innerHTML assigned from variable in popup-ggIvR6cH.js; no CSP to mitigate DOM-XSS.
  • no_developer_name store developer_name is empty string; verified_publisher=true but no display name reduces accountability.
  • ai_extension_page_content manifest AI content exporter processing page content on 7 major AI platforms — elevated data exfil surface.
  • external_js_hosts crx 9 external JS hosts referenced including hertzen.com (html2canvas) and reactjs.org — third-party CDN references.
  • verified_publisher store verified_publisher=true, domain wilds.ai resolves, looks_throwaway=false — positive trust signal.
  • low_installs store Only 47 installs; no ratings; small user base limits community vetting.

Permissions Breakdown

  • downloads medium Can write files to user's download folder; fits stated export function.
  • storage low Local extension storage only; low standalone risk.
  • host: *.character.ai / characterai.io medium Content-script access to AI chat platform; reads conversation data.
  • host: play/api.aidungeon.com medium Access to AI dungeon API + play site; can read/intercept story data.
  • host: janitorai.com / *.janitorai.com medium Access to adult-content AI chat; sensitive conversation data.
  • host: *.chai-ai.com / *.chai.ml medium Access to Chai AI chat platform; reads conversation data.
  • host: chatgpt.com medium Content-script on ChatGPT; can read all chat content visible to user.
  • host: claude.ai medium Content-script on Claude; can read all Claude conversations.
  • host: gemini.google.com medium Content-script on Gemini; can read all Gemini conversations.

Pillar Scores

Permissions3.50
Reputation4.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 05:10
Listing SHA ce01abdedb9a…
Force block — not fired
Score recovered no
Elapsed