ChatGPT to PDF - Export ChatGPT Chats to PDF, Markdown, JSON
poboebmiaakclneagfgfmbakpgcgdfii
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Developer-controlled Cloud Run backend (ai-chat-exporter-api) can receive all exported ChatGPT conversations.
- Gmail dev with no developer name; brand_mention flags ChatGPT impersonation — not a verified publisher.
- Privacy policy is 481 chars, not scoped to this extension, data_collection=false with third_party_silence=true — inadequate.
- CSP connect-src is '*' (wildcard) allowing exfiltration to any endpoint despite MV3.
- Yandex cloud endpoints (yandex.com/.ru) included for storage; data may transit Russian jurisdiction.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'chatgpt'; developer is gmail user, not OpenAI.
- free_webmail_no_devname store developer_email=neocrtxai@gmail.com; developer_name empty; free webmail identity.
- csp_connect_wildcard manifest connect-src * data: blob: filesystem: — effectively unrestricted outbound connections.
- developer_backend_endpoint manifest ai-chat-exporter-api-chatgpt-792277256340.northamerica-south1.run.app in host_permissions and js_external_hosts.
- yandex_cloud_endpoints manifest cloud-api.yandex.net, oauth.yandex.com, oauth.yandex.ru — Russian-jurisdiction cloud storage for user chat data.
- privacy_policy_inadequate api Policy 481 chars; scope_extension=false, data_collection=false, third_party_silence=true.
- install_url_hijack crx install_url_hijack=true; extension opens URL on install.
- search_engine_count_3 api threat_intel.search_engine_count=3 (google, yandex.com, yandex.ru) — not a NewTab, but anomalous.
Permissions Breakdown
- storage low Stores local extension state; low risk on its own.
- downloads medium Can trigger file downloads to user's machine; core to stated PDF export function.
- downloads.open medium Can open downloaded files; low incremental risk but widens download capability.
- identity medium OAuth token access; used for cloud integrations (Dropbox, Google, Notion).
- activeTab low Temporary access to active tab only; scoped correctly to ChatGPT pages.
- host:https://*.amazonaws.com/* medium Broad S3/AWS access; could receive exported chat data.
- host:https://*.googleusercontent.com/* low Google user content CDN; likely for images in exports.
- host:https://*.oaiusercontent.com/* low OpenAI user content; expected for ChatGPT image attachments.
- host:https://ai-chat-exporter-api-*.run.app/* high Developer-controlled backend; all exported chat data could route through here.
- host:https://api.dropboxapi.com/* medium Dropbox integration; chat exports could be sent there.
- host:https://api.notion.com/* medium Notion integration; chat data could be sent.
- host:https://chat.openai.com/* low Primary target domain; expected for content script.
- host:https://chatgpt.com/* low Primary target domain; expected for content script.
- host:https://cloud-api.yandex.net/* medium Yandex cloud storage integration; Russian-hosted endpoint for user data.
- host:https://oauth.yandex.com/* medium Yandex OAuth; enables auth to Russian cloud service.
- host:https://oauth.yandex.ru/* medium Yandex OAuth (.ru TLD); duplicative risk, Russian jurisdiction.
- host:https://www.googleapis.com/* low Google Drive/API integration; standard for export tools.
Pillar Scores
Permissions4.00
Reputation7.50
Network5.50
Webstore5.50
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedn369efcb9dp727562726963xsx | 4.97 | Medium | review | 2026-09-09 |
| v3.6 | 4.52 | Medium | review | 2026-08-31 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 13:36
Listing SHA
28dd71dd02b2…
Force block
— not fired
Score recovered
no
Elapsed
—