Monica: All-In-One AI Assist & Smartest AI Agent
ofpnmcalabcbjgholdjcjblkibolbppb
Risk Score
3.51
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- <all_urls> host permission + scripting enables full page read/write on every site user visits.
- AI extension processes page content and sends it to monica.im — high-value exfil surface.
- No CSP declared (MV3 default helps, but no explicit policy); innerHTML sinks present without CSP hardening.
- Developer name field empty in listing; reduces accountability signal.
- 3M+ install base amplifies any future compromise or policy change.
Evidence
- host_permissions <all_urls> + scripting manifest Extension injects content scripts on every URL; high capability surface for AI data processing.
- AI category + broad host access store Webstore +2.5 AI/Gen-AI extension processing page content; justified-broad discount applied (-1.5).
- dom_sink_innerhtml_userctrl (2 files) crx innerHTML sinks in content.js and monicaPopup.js; no CSP present → FIX B triggers +2.0 code quality.
- csp_present == false, MV3 manifest No explicit CSP; MV3 provides strict default so no +2.0 network penalty, but amplifies innerHTML risk.
- privacy_policy scoped with retention and third-party sharing api Policy fetched, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true → +1.0.
- is_featured_by_google == true store Featured badge provides -2.0 reputation discount; not verified publisher so cap rules don't apply.
- domain_age_ct age_days=1207, cert_count=188 api Domain ~3.3 years old, not new, no domain-age penalty.
- threat_intel clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves, not throwaway.
Permissions Breakdown
- storage low Standard local data persistence; low standalone risk.
- scripting medium Allows dynamic script injection into pages; elevated when paired with <all_urls>.
- sidePanel low UI surface only; no direct data-access capability.
- contextMenus low Adds right-click menu items; minimal risk surface.
- <all_urls> (host_permissions) high Grants content-script access to every site user visits; broad reach for an AI extension.
Pillar Scores
Permissions5.50
Reputation3.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 2.59 | Low | review | 2026-08-15 |
| %22fsssiedxa$'sssiedx | 2.63 | Low | review | 2026-08-15 |
| 'fsssiedxa'sssiedx | 3.27 | Low | review | 2026-08-15 |
| "fsssiedxa sssiedx | 2.68 | Low | review | 2026-08-15 |
| fsssiedxa$"sssiedx | 3.05 | Low | review | 2026-08-15 |
| <fsssiedxa'sssiedx | 2.59 | Low | review | 2026-08-11 |
| <fsssiedxa"sssiedx | 3.04 | Low | review | 2026-08-10 |
| <fsssiedxi sssiedx | 3.02 | Low | review | 2026-08-10 |
| <fsssiedxi'sssiedx | 3.22 | Low | review | 2026-08-10 |
| fsssiedx<sssiedx | 3.10 | Low | review | 2026-08-10 |
| v3.6</script><script>3mK7(9711)</script> | 3.54 | Low | review | 2026-08-05 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 2.70 | Low | review | 2026-08-05 |
| dfb{{98991*97996}}xca | 2.77 | Low | review | 2026-08-05 |
| v3.6'"()&%<zzz><ScRiPt >3mK7(9592)</ScRiPt> | 3.27 | Low | review | 2026-08-05 |
| <fsssiedxa"sssiedx | 3.27 | Low | review | 2026-07-29 |
| <fsssiedxa$"sssiedx | 2.90 | Low | review | 2026-07-29 |
| <fsssiedxa$'sssiedx | 2.59 | Low | review | 2026-07-29 |
| <fsssiedxa'sssiedx | 2.77 | Low | review | 2026-07-29 |
| <fsssiedxa xx psssiedx | 2.54 | Low | review | 2026-07-29 |
| fsssiedxa<sssiedx | 3.40 | Low | review | 2026-07-29 |
| sssieddrubricxsx | 3.20 | Low | review | 2026-07-29 |
| v3.6 | 3.51 | Low | review | 2026-06-16 |
| v3.4-rev | 4.12 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
8897b23a099a…
Force block
— not fired
Score recovered
no
Elapsed
27.5s