Echoes ChatGPT, Claude & more Tool for Search, Tag, Export & Summarize
ppnfnillfndkellpbphafglnljdefjph
Risk Score
5.58
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies permission on major AI platforms (OpenAI, Claude, Gemini) enables session token theft
- Privacy policy is generic freeprivacypolicy.com template: admits data collection + 3rd-party sharing, not scoped to this extension → Privacy pillar 10.0
- Brand impersonation: lists ChatGPT, Claude, Gemini in title without verified ownership of those brands
- No CSP (MV3 no penalty but null CSP) + 4 innerHTML DOM-XSS sinks across dashboard, chat, popup, and demo JS
- Content scripts run on all major AI platforms with cookies access — AI conversation exfil surface is high
Evidence
- cookies + AI platform host_permissions manifest cookies declared + host_permissions covering chatgpt.com, claude.ai, gemini.google.com, deepseek.com, grok.com
- brand_impersonation store brand_mention.is_impersonation=true; brands: chatgpt, claude, gemini; confirmed_owner=false; verified_publisher mitigates partially
- generic_privacy_policy api freeprivacypolicy.com hosted policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy
- dom_xss_sinks crx 4 files with dom_sink_innerhtml_userctrl; no CSP present to mitigate; elevated code quality risk
- is_featured_by_google + verified_publisher store Both verified_publisher=true and is_featured_by_google=true; reduces reputation risk but capped by impersonation signal
- js_external_hosts crx 12 external hosts including tinyurl.com, feross.org, www.maisieai.com, reactjs.org — >3 distinct domains
- no_developer_name store developer_name is empty string; email echoes.support@r2bits.com at resolving domain
- ai_extension_page_content manifest AI-category extension with content_scripts on all major AI chat platforms processes conversation content
Permissions Breakdown
- scripting medium Can inject scripts into AI platform pages via host_permissions; scoped to declared hosts.
- activeTab low Temporary access to current tab; lower risk with scripting.
- storage low Local data persistence; standard for organizer tools.
- cookies high Can read session cookies on declared AI platform hosts including OpenAI and Google.
- notifications low User-visible alerts only.
- declarativeNetRequest medium Can block/redirect network requests; less invasive than webRequest but still notable.
- alarms low Background scheduling; low standalone risk.
- host:https://chat.openai.com/* high Content script + cookies on OpenAI — can read conversations and session tokens.
- host:https://chatgpt.com/* high Content script + cookies on ChatGPT domain.
- host:https://claude.ai/* high Content script + cookies on Anthropic Claude.
- host:https://gemini.google.com/* high Content script + cookies on Google Gemini.
- host:https://www.google-analytics.com/* medium Analytics endpoint; extension can send data to GA.
- host:https://vercel-r2bits.vercel.app/* medium Dev-controlled backend on Vercel; potential data relay.
- host:https://chatgpt-conversation-search.firebaseapp.com/* medium Firebase backend; scoped but third-party cloud.
Pillar Scores
Permissions6.50
Reputation5.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| sssiedn39f20669dp727562726963xsx | 4.11 | Medium | review | 2026-09-09 |
| v3.6 | 5.58 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA
f9517834fe92…
Force block
— not fired
Score recovered
no
Elapsed
35.5s