CRX aminer
Extension icon

Google Apps Script Copilot

Version 2.1.0 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Developer: gscopilot.com
Rating: 3.7 ★ (21 ratings)
Users: 10,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a moderate user base of 10,000 users but a concerning rating of only 3.7 out of 5 stars from 21 reviews, suggesting user dissatisfaction. The developer domain gscopilot.com appears to be a specialized service for Google Apps Script assistance, which aligns with the extension's purpose. However, the relatively low rating raises questions about the extension's quality or trustworthiness.

Concerns:

The extension requests excessive permissions that far exceed what would be necessary for a Google Apps Script assistant. The identity permission allows access to your Google account information, while the cookies permission can read and modify all browser cookies across sites. The combination of these permissions with access to Google's authentication domains creates significant privacy and security risks. The broad host permissions and access to sensitive Google domains (script.google.com and accounts.google.com) could enable unauthorized access to your Google Apps Script projects and account credentials.

Recommendations:

Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with minimal personal data and no saved passwords. Consider alternative Google Apps Script tools that require fewer permissions. Monitor your Google account activity closely if you choose to proceed. The permission set suggests potential overreach that could compromise your Google account security and broader web browsing privacy.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://script.google.com/*, https://accounts.google.com/. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.