SideAll: Chat Sidebar - GPT, Claude, DeepSeek
pdebmboeclmkhcbldifomfpekphdmlgb
Risk Score
3.67
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: extension name/description references Claude and DeepSeek without confirmed ownership.
- declarativeNetRequestWithHostAccess + content scripts on 9 major AI platforms (ChatGPT, Claude, Gemini, etc.) — can intercept/modify sensitive AI conversations.
- Uninstall URL hijack detected — extension sets a third-party uninstall URL.
- dom_sink_innerhtml_userctrl in content context creates DOM-XSS risk on AI chat pages.
- No developer display name; AI extension processing page content on high-value targets.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; mentions Claude, DeepSeek without confirmed_owner=true.
- uninstall_url_hijack crx uninstall_url_hijack=true; chrome.runtime.setUninstallURL() targeting third party.
- declarativeNetRequestWithHostAccess manifest HIGH permission + host_permissions on 9 major AI platforms enables request interception/modification.
- content_scripts_on_ai_platforms manifest Content scripts injected into ChatGPT, Claude, Gemini, Grok, Copilot, DeepSeek, Mistral, Meta AI.
- dom_sink_innerhtml crx innerHTML used from variable in content script chunk; DOM-XSS risk on AI chat pages.
- verified_publisher store verified_publisher=true; developer domain sideall.app resolves and is not throwaway.
- privacy_policy api Policy fetched, scoped to extension, documents data collection and retention; third_party_sharing=true.
- geo_diversity crx JS hosts span 4 countries (CA, DE, FR, US); +1.5 network penalty applied.
Permissions Breakdown
- identity low OAuth token access; low risk without broad scopes declared.
- sidePanel low UI surface only; no data access granted.
- storage low Local extension storage; standard for settings persistence.
- contextMenus low Adds right-click menu items; limited risk surface.
- declarativeNetRequest medium Can modify network requests via static rules; lower risk than webRequest.
- declarativeNetRequestWithHostAccess high Can modify requests on declared AI-platform hosts; combined with host_permissions raises risk.
- host_permissions: AI platform domains high Content scripts + declarativeNetRequestWithHostAccess on 9 major AI platforms (ChatGPT, Claude, Gemini, etc.).
Pillar Scores
Permissions4.50
Reputation6.50
Network3.50
Webstore5.00
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA
0afb06784aba…
Force block
— not fired
Score recovered
no
Elapsed
25.0s