The extension is developed by Anthropic, a reputable AI company known for Claude AI assistant, which adds credibility. However, the 6 million user base is offset by a concerning low rating of 2.7 stars from 838 reviews, suggesting significant user dissatisfaction or functionality issues. The legitimate company backing doesn't eliminate the security concerns posed by the extensive permissions.
The permission set is extremely broad and invasive for an AI assistant extension. The debugger permission is particularly alarming as it allows manipulation of other extensions and browser debugging capabilities. The combination of all_urls host permissions with broad content script injection creates a surveillance-capable extension that can monitor and interact with every website you visit. The identity permission coupled with downloads access could enable data exfiltration. The webNavigation permission allows complete browsing behavior tracking. Many of these permissions appear unnecessary for a typical AI chat interface.
Given the critical risk level, strongly consider running this extension in a completely separate Chrome profile dedicated solely to Claude interactions. Alternatively, use Claude directly through their website rather than the extension. If you must use the extension, regularly audit what data it might be accessing and consider using it only when specifically needed, disabling it otherwise. Monitor your browser's security settings and be cautious about sensitive activities while the extension is active.
| https://github.com/jnordberg/gif.js | http://www.w3.org/2000/svg | |
| https://clients2.google.com/service/update2/crx | https://claude.ai/ | |
| https://api.anthropic.com | https://claude.ai | |
| https://platform.claude.com | https://api.segment.io | |
| https://api.honeycomb.io | https://browser-intake-us5-datadoghq.com | |
| https://example.com | https://api.vimeo.com/videos/ | |
| https://www.googleapis.com/youtube/v3/videos?id= | https://github.com/mermaid-js/mermaid/releases/tag/v11.0.0 | |
| https://tailwindcss.com | https://github.com/mermaid-js/mermaid/issues. | |
| https://docs.expo.dev/versions/latest/sdk/expo/#expofetch-api | https://github.com/anthropics/anthropic-sdk-typescript#streaming-responses | |
| https://github.com/anthropics/anthropic-sdk-typescript#long-requests | http://www.w3.org/1999/xlink | |
| http://www.w3.org/1998/Math/MathML | http://www.w3.org/1999/xhtml | |
| https://chromewebstore.google.com/detail/claude/dngcpimnedloihjnnfngkgjoidhnaolf | https://nextjs.org/docs/messages/invalid-images-config | |
| https://nextjs.org/docs/messages/next-image-missing-loader | https://www.google.com/s2/favicons?domain= | |
| https://mcp-server-gcal-586545259222.us-central1.run.app/sse | https://mcp-server-gcal-586545259222.us-central1.run.app/mcp | |
| https://gcal.mcp.claude.com/mcp | https://calendarmcp.googleapis.com/mcp/v1 | |
| https://mcp-server-gmail-110131437935.us-central1.run.app/sse | https://mcp-server-gmail-110131437935.us-central1.run.app/mcp | |
| https://gmail.mcp.claude.com/mcp | https://gmailmcp.googleapis.com/mcp/v1 | |
| https://api.anthropic.com/mcp/gdrive/sse | https://api.anthropic.com/mcp/gdrive/mcp | |
| https://drivemcp.googleapis.com/mcp/v1 | https://drivemcp.googleapis.com/mcp | |
| https://mcp-server-gdrive-532483229523.us-central1.run.app/sse | https://slack.mcp.ant.dev/sse | |
| https://gcal.mcp.staging.ant.dev/mcp | https://gmail.mcp.staging.ant.dev/mcp | |
| https://microsoft365.mcp.claude.com/mcp | https://www.microsoft.com/microsoft-365 | |
| https://www.google.com/s2/favicons | https://www.gstatic.com | |
| https://t0.gstatic.com | https://github.com/syntax-tree/hast-util-to-jsx-runtime | |
| https://docs.datadoghq.com | https://www.datadoghq-browser-agent.com | |
| https://www.datad0g-browser-agent.com | https://d3uc069fcn7uxw.cloudfront.net | |
| https://d20xtzwzcl0ceb.cloudfront.net | https://github.com/uuidjs/uuid#getrandomvalues-not-supported | |
| https://support.claude.com/en/articles/12012173-getting-started-with-claude-for-chrome#h_91c6e5a1ee | https://claude.ai/settings/integrations | |
| https://claude.ai/upgrade?hide_free=true | https://prosemirror.net/docs/guide/#generatable | |
| https://support.anthropic.com/en/articles/8525154-claude-is-providing-incorrect-or-misleading-responses-what-s-going-on | https://support.claude.com/en/articles/10023548-how-long-do-you-store-my-data | |
| https://claude.ai/settings/connectors | https://claude.ai/api/desktop/darwin/universal/dmg/latest/redirect | |
| https://claude.ai/download | https://claude.com/product/cowork | |
| https://chromewebstore.google.com/ | https://claude.ai/settings/usage | |
| https://www.anthropic.com/legal/aup | http://www.w3.org/XML/1998/namespace | |
| https://docs.google.com/forms/d/e/1FAIpQLSdLa1wTVkB2ml2abPI1FP9KiboOnp2N0c3aDmp5rWmaOybWwQ/viewform | http://www.w3.org/2000/xmlns/ | |
| https://github.com/markedjs/marked. | https://github.com/mermaid-js/mermaid | |
| https://claude.com/form/anthropic-content-reporting | https://cdn.segment.com | |
| https://cdn.segment. | https://nextjs.org/docs/messages/public-next-folder-conflict | |
| https://nextjs.org/docs/messages/404-get-initial-props | https://nextjs.org/docs/messages/gssp-export | |
| https://nextjs.org/docs/messages/gssp-component-member | https://nextjs.org/docs/messages/non-standard-node-env |
{ "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjU1XnLPoasGVmZU42K3h6S+sQhkogfcoLPbIcrWH5Oo8QoInBIugkew/7cWaEFySyQrkaEBe1fjeS/rlAqd3r778dKcTvDZcXmj0VVX0Fi1i8tnkarurceGKGdVxfkL7e30nwfgwoPxj3H8OQbsbxFcBWGVtcFekmdpiyaxwz6o4yXIWColfAxh9K2yToOZkoAS5GvgGvTexiCh1gYy++eFdk6C61mcFsyDdoGQtduhGEaX0zZ9uAW1jX4JTPmHV3kEFrZu/WVBl7Obw+Jk/osoHMdmghVNy6SCB8/6mcgmxkP9buPrNUZgYP6n0x5dqEJ2Ecww/lb1Zd4nQf4XGOwIDAQAB", "name": "Claude", "icons": { "128": "icon-128.png" }, "action": { "default_title": "Open Claude" }, "storage": { "managed_schema": "managed_schema.json" }, "version": "1.0.69", "commands": { "toggle-side-panel": { "description": "Toggle Claude side panel", "suggested_key": { "mac": "Command+E", "default": "Ctrl+E" } } }, "background": { "type": "module", "service_worker": "service-worker-loader.js" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "Claude in Chrome (Beta)", "permissions": [ "sidePanel", "storage", "activeTab", "scripting", "debugger", "tabGroups", "tabs", "alarms", "notifications", "webNavigation", "declarativeNetRequestWithHostAccess", "offscreen", "nativeMessaging", "unlimitedStorage", "downloads", "identity" ], "options_page": "options.html", "content_scripts": [ { "js": [ "assets/content-script.ts-Bwa5rY9t.js" ], "run_at": "document_end", "matches": [ "https://claude.ai/*", "https://*.claude.ai/*" ] }, { "js": [ "assets/accessibility-tree.js-D8KNCIWO.js" ], "run_at": "document_start", "matches": [ "<all_urls>" ], "all_frames": true }, { "js": [ "assets/agent-visual-indicator.js-Ct7LqXhp.js" ], "run_at": "document_idle", "matches": [ "<all_urls>" ], "all_frames": false } ], "host_permissions": [ "<all_urls>" ], "manifest_version": 3, "externally_connectable": { "matches": [ "https://claude.ai/*", "https://*.claude.ai/*" ] }, "minimum_chrome_version": "116", "content_security_policy": { "extension_pages": "script-src 'self'; object-src 'self'; connect-src 'self' https://api.anthropic.com wss://api.anthropic.com https://claude.ai https://platform.claude.com https://api.segment.io https://*.segment.com https://*.ingest.us.sentry.io https://api.honeycomb.io https://browser-intake-us5-datadoghq.com wss://bridge.claudeusercontent.com wss://bridge-staging.claudeusercontent.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:;" }, "web_accessible_resources": [ { "matches": [ "https://*.claude.ai/*", "https://claude.ai/*" ], "resources": [ "assets/content-script.ts-Bwa5rY9t.js" ], "use_dynamic_url": false }, { "matches": [ "<all_urls>" ], "resources": [ "assets/accessibility-tree.js-D8KNCIWO.js", "assets/agent-visual-indicator.js-Ct7LqXhp.js" ], "use_dynamic_url": false } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.