CRX aminer
Extension icon

Clay for Chrome

Version 1.0.0 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Developer: clay.com
Rating: 4.9 ★ (8 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension comes from clay.com, which appears to be a legitimate company with a professional domain. The 4.9-star rating suggests user satisfaction, though with only 8 reviews the sample size is quite small. The 10,000 user base indicates moderate adoption. However, this is version 1.0.0, suggesting it's a relatively new extension which may not have undergone extensive real-world testing.

Concerns:

The combination of broad host permissions (*://*/*) with clipboard write access creates significant privacy risks. The extension can access all websites and modify clipboard content, potentially capturing sensitive information like passwords or personal data. The tabs permission allows monitoring and manipulation of browsing activity across all sites. While these permissions might be necessary for Clay's functionality (likely a productivity or automation tool), they create a powerful surveillance capability. The content script injection on clay.run domains suggests legitimate business use, but the broad permissions extend far beyond this scope.

Recommendations:

Given the high-risk permission combination, consider running this extension in a separate Chrome profile dedicated to Clay-related work. Regularly review what data you copy to your clipboard while the extension is active. Monitor the extension's behavior and disable it when not actively using Clay services. Consider whether the productivity benefits justify the privacy trade-offs, and evaluate if Clay's web interface could meet your needs instead of the browser extension.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.