Version 0.10.137 View in Chrome Web Store
The extension comes from nudgesecurity.com, which appears to be a legitimate security company. With 90,000 users and a perfect 5.0 rating, it shows some adoption, though the single review count raises questions about the rating's reliability. The company appears to focus on security solutions, which provides some context for the extensive permissions.
The extension requests an extremely broad set of permissions that far exceed what most legitimate extensions require. The combination of management permissions (can control other extensions), webRequest interception, clipboard access, identity information, and universal host permissions creates a perfect storm for potential abuse. The content script injection across numerous AI platforms and email services (Gmail, Outlook) suggests comprehensive monitoring capabilities. The geolocation permission seems unnecessary for a security tool, and the ability to access downloads and web navigation history provides extensive tracking capabilities.
Most concerning is the <all_urls> permission appearing multiple times, granting unrestricted access to every website you visit. For a security extension, this level of access could be justified but requires absolute trust in the vendor.
Given the critical risk level, run this extension in a completely separate Chrome profile dedicated solely to security monitoring if you must use it. Never use this profile for personal browsing, banking, or sensitive activities. Verify the extension's legitimacy directly with Nudge Security before installation. Consider whether the security benefits truly justify such extensive system access. Monitor your system closely for any unusual activity after installation.
| https://reactjs.org/docs/error-decoder.html?invariant= | http://www.w3.org/1999/xlink | |
| http://www.w3.org/XML/1998/namespace | http://www.w3.org/2000/svg | |
| http://www.w3.org/1998/Math/MathML | http://www.w3.org/1999/xhtml | |
| https://fonts.googleapis.com/css2?family=Inter:wght@300 | http://jedwatson.github.io/classnames | |
| https://fb.me/react-async-component-lifecycle-hooks | http://fb.me/use-check-prop-types | |
| https://github.com/remarkjs/react-markdown/blob/main/changelog.md | https://feross.org | |
| https://groq.com/ | https://groq.com | |
| https://console.groq.com/ | https://console.groq.com | |
| https://content-push.googleapis.com/upload | https://push.clients6.google.com/upload/ | |
| https://manus.im/app | https://api.manus.im/api/chat/uploadComplete | |
| https://www.notion.so/ai | https://www.notion.so/chat | |
| https://www.notion.so/chat? | https://www.notion.so/ | |
| https://copilot.microsoft.com/chats/ | https://copilot.microsoft.com | |
| https://chatgpt.com/ | https://chatgpt.com | |
| https://chatgpt.com/c/ | https://chatgpt.com/g/ | |
| https://chatgpt.com/canvas/ | https://claude.ai/ | |
| https://claude.ai | https://claude.ai/new | |
| https://claude.ai/chat | https://claude.ai/project | |
| https://v0.dev/ | https://v0.dev | |
| https://v0.dev/chat | https://v0.app/ | |
| https://v0.app | https://v0.app/chat | |
| https://app.napkin.ai/ | https://app.napkin.ai | |
| https://notebooklm.google.com/ | https://notebooklm.google.com/notebook/ | |
| https://dashboard.cohere.com/playground/ | https://dashboard.cohere.com/playground/chat | |
| https://chat.cerebras.ai/ | https://chat.cerebras.ai | |
| https://nova.amazon.com/ | https://nova.amazon.com | |
| https://poe.com/ | https://poe.com | |
| https://www.poe.com/ | https://www.poe.com | |
| https://chat.baidu.com/ | https://chat.baidu.com | |
| https://vertexaisearch.cloud.google.com/home/ | https://chat.chaton.ai/ | |
| https://chat.chaton.ai | https://venice.ai/ | |
| https://venice.ai | https://app.hubspot.com/ | |
| https://apps.abacus.ai/ | https://apps.abacus.ai/chatllm | |
| https://lovable.dev/ | https://lovable.dev | |
| https://gemini.google.com/ | https://gemini.google.com/app | |
| https://inference.cerebras.ai/ | https://inference.cerebras.ai | |
| https://gamma.app/ | https://gamma.app/create | |
| https://gamma.app/generate | https://playground.liquid.ai/ | |
| https://playground.liquid.ai/chat | https://kimi.com/ | |
| https://kimi.com/chat | https://www.kimi.com/ |
{ "name": "Nudge Security Browser Extension", "icons": { "16": "icon16.plasmo.6c567d50.png", "32": "icon32.plasmo.76b92899.png", "48": "icon48.plasmo.aced7582.png", "64": "icon64.plasmo.8bb5e6e0.png", "128": "icon128.plasmo.3c1ed2d2.png" }, "action": { "default_icon": { "16": "icon16.plasmo.6c567d50.png", "32": "icon32.plasmo.76b92899.png", "48": "icon48.plasmo.aced7582.png", "64": "icon64.plasmo.8bb5e6e0.png", "128": "icon128.plasmo.3c1ed2d2.png" } }, "author": "Nudge Security, Inc.", "storage": { "managed_schema": "schema.27ce56aa.json" }, "version": "0.10.137", "background": { "service_worker": "static/background/index.js" }, "options_ui": { "page": "options.html", "open_in_tab": true }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "Nudge Security browser helper.", "permissions": [ "storage", "scripting", "tabs", "notifications", "management", "webRequest", "geolocation", "offscreen", "alarms", "identity", "identity.email", "clipboardRead", "downloads", "webNavigation", "idle" ], "content_scripts": [ { "js": [ "ai-monitoring.7cdfa8a5.js" ], "css": [], "run_at": "document_start", "matches": [ "https://chatgpt.com/*", "https://claude.ai/*", "https://v0.dev/*", "https://v0.app/*", "https://dashboard.cohere.com/playground/*", "https://chat.cerebras.ai/*", "https://nova.amazon.com/*", "https://chat.baidu.com/*", "https://chat.chaton.ai/*", "https://venice.ai/*", "https://app.hubspot.com/*", "https://apps.abacus.ai/*", "https://lovable.dev/*", "https://gemini.google.com/*", "https://inference.cerebras.ai/*", "https://gamma.app/*", "https://playground.liquid.ai/*", "https://kimi.com/*", "https://www.kimi.com/*", "https://kimi.moonshot.cn/*", "https://aistudio.google.com/prompts/*", "https://www.phind.com/*", "*://grok.com/*", "https://x.ai/*", "https://poe.com/*", "https://www.poe.com/*", "https://mistral.ai/*", "https://chat.mistral.ai/*", "https://www.meta.ai/*", "https://chat.qwen.ai/*", "https://qwen.ai/*", "https://www.perplexity.ai/*", "https://api.together.ai/playground/v2/chat/*", "https://chat.deepseek.com/*", "https://copilot.microsoft.com/*", "https://copilot.microsoft.com/chats/*", "https://copilot.cloud.microsoft/*", "https://julius.ai/*", "https://m365.cloud.microsoft/chat/*", "https://chat.z.ai/*", "https://github.com/spark/*", "https://www.ravenala.ai/*", "https://www.blackbox.ai/*", "https://chatbot.app/*", "https://chatbotapp.ai/*", "https://ai.zoom.us/*", "https://confer.to/*", "https://quillbot.com/*", "https://app.napkin.ai/*", "https://notebooklm.google.com/*", "https://www.notion.so/ai", "https://www.notion.so/chat", "https://www.notion.so/chat?*", "https://www.notion.so/*", "https://huggingface.co/chat/*", "https://chat.chatbot.app/*", "https://chat.chatbotapp.ai/*", "https://api.manus.im/*", "https://manus.im/*", "https://manus.im/app/*", "https://genspark.ai/*", "https://www.genspark.ai/*", "https://ernie.baidu.com/*", "https://app.txyz.ai/*", "https://k2think.ai/*", "https://www.k2think.ai/*", "https://vertexaisearch.cloud.google.com/home/*", "https://askaichat.app/*", "https://agent.minimax.io/*", "https://app.writer.com/*", "https://www.typingmind.com/*", "https://typingmind.com/*", "https://typingmind.io/*", "*://*.typingmind.io/*" ] }, { "js": [ "ai-monitoring-all-frames.712678b2.js" ], "css": [], "run_at": "document_start", "matches": [ "https://groq.com/*", "https://console.groq.com/*" ], "all_frames": true }, { "js": [ "content.40ff0a94.js" ], "css": [], "matches": [ "<all_urls>" ], "all_frames": true }, { "js": [ "detect-failed-auth.4b8f93ce.js" ], "css": [], "run_at": "document_idle", "matches": [ "<all_urls>" ], "all_frames": true }, { "js": [ "detect-login-page.2810e686.js" ], "css": [], "run_at": "document_start", "matches": [ "<all_urls>" ] }, { "js": [ "registration.86223a0b.js" ], "css": [], "matches": [ "https://mail.google.com/*", "https://outlook.live.com/*", "https://outlook.office.com/*" ] }, { "js": [ "EventingNudge.c92f3be1.js" ], "css": [], "matches": [ "<all_urls>" ] }, { "js": [ "Nudge.4d07f2ec.js" ], "css": [], "matches": [ "<all_urls>" ] } ], "host_permissions": [ "https://*/*", "http://*/*" ], "manifest_version": 3, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "assets/*.png", "assets/*.json" ] }, { "matches": [ "https://*.nudgesecurity.io/*" ], "resources": [ "tabs/*" ] }, { "matches": [ "<all_urls>" ], "resources": [ "EventingNudge.2dcdc5fd.css", "EventingNudge.6e038a4b.css" ] }, { "matches": [ "<all_urls>" ], "resources": [ "EventingNudge.2dcdc5fd.css", "EventingNudge.6e038a4b.css" ] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.