Microsoft Copilot to PDF - Export Microsoft Copilot Chats to PDF, Markdown
nghpoklfiggkdemkmgllkaaiemggmdao
Risk Score
4.83
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: uses 'Microsoft' and 'Copilot' in name; developer is gmail user with no confirmed affiliation.
- Free-webmail developer (gmail) with no verified publisher badge; no developer name supplied.
- Privacy policy is too short (481 chars), not scoped to this extension, and does not disclose data collection — scores as near-absent.
- 8 innerHTML DOM-XSS sinks across content scripts that process AI chat HTML; chat content piped through developer Cloud Run API.
- Yandex cloud integration (Russian jurisdiction) and broad multi-cloud routing (AWS, Dropbox, Notion, Google Drive) of sensitive chat data.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands=['microsoft','copilot']; developer domain=gmail.com, confirmed_owner=false.
- free_webmail_no_devname store developer_email=neocrtxai@gmail.com; developer_name=''; no verified publisher; floor reputation >= 7.5.
- privacy_policy_inadequate api Policy fetched; length=481; scope_extension=false; data_collection=false; third_party_silence=true — near-generic stub.
- dom_xss_sinks crx 8 innerHTML user-controlled sinks across 8 JS files; CSP connect-src=* does not block DOM-XSS exploitation.
- install_url_hijack manifest install_url_hijack=true; extension opens a URL on install (target=null in listing data).
- broad_connect_src manifest CSP connect-src=* allows extension pages to contact any host; elevates network exfil risk.
- yandex_integration manifest host_permissions include cloud-api.yandex.net, oauth.yandex.com, oauth.yandex.ru — Russian jurisdiction data routing.
- developer_api_backend manifest ai-chat-exporter-api-microsoft-copilot-792277256340.northamerica-south1.run.app in both host_permissions and js_external_hosts.
Permissions Breakdown
- storage low Stores user settings locally; standard low-risk API.
- downloads medium Can initiate file downloads to user machine; needed for PDF export.
- downloads.open medium Can auto-open downloaded files; elevates downloads risk slightly.
- identity medium OAuth token access; can request Google identity scopes.
- activeTab low Scoped to user-activated tab only; limited surface.
- host:*.amazonaws.com medium Broad AWS endpoint; could reach any AWS-hosted backend.
- host:*.googleusercontent.com medium Broad Google user-content domain; needed for Drive integration.
- host:ai-chat-exporter-api-* medium Developer-controlled Cloud Run API receiving exported chat content.
- host:api.dropboxapi.com + content.dropboxapi.com medium Dropbox upload integration; chat content routed externally.
- host:api.notion.com medium Notion integration; chat data may be written to user workspace.
- host:cloud-api.yandex.net + oauth.yandex.* medium Yandex cloud integration; Russian jurisdiction data routing concern.
- host:copilot.com + copilot.microsoft.com + m365.* medium Primary stated function; content scripts run here reading chat data.
- host:www.googleapis.com medium Google API access for Drive/Docs export integration.
Pillar Scores
Permissions3.30
Reputation7.50
Network4.50
Webstore6.00
Maintenance0.00
Privacy9.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 13:29
Listing SHA
73f8a44ef9a0…
Force block
— not fired
Score recovered
no
Elapsed
—