CRX aminer
Extension icon

Claude

Version 1.0.69 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Developer: Anthropic
Rating: 2.7 ★ (838 ratings)
Users: 6,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension is developed by Anthropic, a reputable AI company known for Claude AI assistant, which adds credibility. However, the 6 million user base is offset by a concerning low rating of 2.7 stars from 838 reviews, suggesting significant user dissatisfaction or functionality issues. The legitimate company backing doesn't eliminate the security concerns posed by the extensive permissions.

Concerns:

The permission set is extremely broad and invasive for an AI assistant extension. The debugger permission is particularly alarming as it allows manipulation of other extensions and browser debugging capabilities. The combination of all_urls host permissions with broad content script injection creates a surveillance-capable extension that can monitor and interact with every website you visit. The identity permission coupled with downloads access could enable data exfiltration. The webNavigation permission allows complete browsing behavior tracking. Many of these permissions appear unnecessary for a typical AI chat interface.

Recommendations:

Given the critical risk level, strongly consider running this extension in a completely separate Chrome profile dedicated solely to Claude interactions. Alternatively, use Claude directly through their website rather than the extension. If you must use the extension, regularly audit what data it might be accessing and consider using it only when specifically needed, disabling it otherwise. Monitor your browser's security settings and be cautious about sensitive activities while the extension is active.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.