CRX aminer
Extension icon

Obsidian Web Clipper

Version 1.6.1 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Developer: obsidian.md
Rating: 4.8 ★ (499 ratings)
Users: 700,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension is developed by obsidian.md, the official team behind the popular Obsidian note-taking application, which adds significant credibility. With 700,000 users and a strong 4.8-star rating from 499 reviews, it demonstrates good user satisfaction and adoption. The extension serves a legitimate purpose as a web clipper for the Obsidian ecosystem.
Concerns: The extension requests extremely broad permissions that exceed typical web clipper requirements. The combination of all_urls host permissions with clipboardWrite access creates potential for data exfiltration - it could theoretically copy sensitive information from any website to the clipboard. The activeTab permission, while common, combined with broad host access allows interaction with any website content. The scripting permission enables code injection across all sites, which could be misused if the extension were compromised.
Recommendations: Given the high-risk permission profile, consider running this extension in a dedicated Chrome profile separate from sensitive browsing activities like banking or work-related tasks. Monitor clipboard contents after using the extension to ensure no unexpected data is copied. Regularly review the extension's behavior and updates from the developer. If you only clip from specific sites, consider whether a more limited web clipper might meet your needs. The official developer status provides some assurance, but the broad permissions warrant caution with sensitive data.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.