Thir - Intelligent ChatGPT AI Assistant (Gemini, Grok, Claude, DeepSeek)
neecnojgdjbkphlalgfgegmhkhakgkob
Risk Score
5.84
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: title invokes ChatGPT, Gemini, Claude, DeepSeek without ownership — classic AI wrapper impersonation.
- Privacy policy URL returns connection error; policy effectively unavailable — scores as unfetched (10.0).
- AI extension with scripting + <all_urls> can read/exfiltrate page content across all sites visited.
- Search provider override registered for Thir search engine; routes user queries through developer-controlled endpoint.
- Only 10 installs with HIGH-tier permissions and no dev name — small-install/high-perm anomaly flagged.
Evidence
- brand_impersonation store brands_mentioned=[chatgpt,gemini,claude,deepseek]; confirmed_owner=false; is_impersonation=true.
- privacy_policy_fetch_failed api fetch_error:ConnectionError on https://thir.app/legal/privacy; policy treated as unavailable.
- scripting_plus_all_urls manifest scripting permission + <all_urls> host_permission; can inject JS on every site.
- search_provider_override manifest chrome_settings_overrides.search_provider routes queries to https://thir.app/?q={searchTerms}.
- no_developer_name store developer_name is empty string; identity accountability reduced.
- install_perm_anomaly api install_count=10 with has_high_tier_permission=true; small_install_high_perm=true.
- ai_extension_page_content store AI assistant with broad content_scripts on all_urls; page content accessible to developer backend.
- verified_publisher store verified_publisher=true; partial reputation credit but does not override impersonation/privacy gaps.
Permissions Breakdown
- sidePanel low UI surface only; low intrinsic risk.
- activeTab medium Grants access to current tab on user action; limited scope.
- scripting high Can inject arbitrary JS into pages; high risk when paired with <all_urls>.
- <all_urls> (host_permission) high Broad host access amplifies scripting/activeTab; can read/modify all sites.
- chrome_settings_overrides.search_provider medium Registers Thir as a search provider; not set as default but still modifies browser search.
Pillar Scores
Permissions6.50
Reputation7.00
Network2.00
Webstore7.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:37
Listing SHA
ebbea589a097…
Force block
— not fired
Score recovered
no
Elapsed
—