AI RTL (فارسی) | راستچین و بهینهسازی بیش از ۵۰ هوش مصنوعی
pjpmebofipgpjaincgoboibbmicccbne
Risk Score
3.43
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Content scripts injected into 40+ major AI platforms (ChatGPT, Claude, Gemini, Copilot) enabling session content read/write.
- Uninstall and install URL hijack flags set — could redirect users to third-party pages on install/uninstall.
- Privacy policy admits data collection and third-party sharing but hosted on Google Sites (free hosting, reduced accountability).
- No developer name listed; Gmail-based dev email reduces accountability for an extension with significant AI platform reach.
- innerHTML sinks in options.js and popup.js without CSP present — DOM-XSS risk, especially relevant given AI content injection scope.
Evidence
- content_scripts_broad_ai_platforms manifest Content scripts match 40+ AI/productivity sites including chatgpt.com, claude.ai, gemini.google.com, copilot.microsoft.com.
- uninstall_and_install_url_hijack crx Both uninstall_url_hijack and install_url_hijack are true; targets null but flags are present — monetization/redirect risk.
- gmail_dev_no_name store Developer email is free webmail (gmail.com); developer_name is empty — low accountability signal.
- privacy_policy_data_collection_third_party api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false. Hosted on Google Sites.
- dom_xss_sink_no_csp crx innerHTML sinks in options.js and popup.js; csp_present=false on MV3 extension — no mitigation layer.
- js_external_hosts crx External hosts: addons.mozilla.org, ai-rtl.ir, donate.sudoshz.ir, mui.com — 4 distinct domains including a donation host.
- verified_publisher store verified_publisher=true; partially offsets reputation concerns from gmail email and no developer name.
- no_cve_findings crx cve_findings_raw empty; jquery 3.7.1 bundled (patched version, no known CVEs).
Permissions Breakdown
- storage low Local config/preference storage only; minimal risk.
- host_permissions: https://ai-rtl.ir/* medium Dev-owned domain; needed for extension backend communication.
- host_permissions: https://api.ai-rtl.ir/* medium Dev-owned API endpoint; scoped but outbound data flow possible.
- host_permissions: https://chatgpt-rtl.ir/* medium Secondary dev domain; brand-adjacent naming adds minor confusion risk.
- host_permissions: https://api.chatgpt-rtl.ir/* medium Secondary dev API; same data-flow risk as api.ai-rtl.ir.
- content_scripts on 40+ AI platforms high Scripts injected into ChatGPT, Claude, Gemini, Copilot etc. — broad read/write of AI session content.
Pillar Scores
Permissions3.50
Reputation5.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 12:01
Listing SHA
75722475ac08…
Force block
— not fired
Score recovered
no
Elapsed
—