Starting analysis...
The extension is developed by Anthropic, a reputable AI company known for Claude AI assistant, which adds credibility. However, the 2.7-star rating from 488 reviews is concerning and suggests user dissatisfaction. With 2 million users, it has significant adoption, but the poor rating indicates potential issues with functionality or user experience.
The extension requests an excessive number of high-risk permissions that seem unnecessary for a typical AI assistant interface. The debugger permission is particularly alarming as it can manipulate other extensions and applications. The combination of broad host permissions (<all_urls>) with content script injection capabilities creates a powerful surveillance and data collection mechanism. The tabs, webNavigation, and downloads permissions enable comprehensive browsing activity monitoring. The poor user rating suggests the extension may not be functioning as expected, which could indicate security or privacy issues.
Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with minimal sensitive data and browsing activity. Consider using Claude AI through their official website instead of this extension. Monitor the extension's behavior closely and revoke permissions if possible. The combination of poor ratings and excessive permissions suggests this extension may not be the official Anthropic product or may have been compromised.
| https://github.com/jnordberg/gif.js | http://www.w3.org/2000/svg | |
| https://clients2.google.com/service/update2/crx | https://claude.ai/ | |
| https://api.anthropic.com | https://claude.ai | |
| https://platform.claude.com | https://api.segment.io | |
| https://api.honeycomb.io | https://browser-intake-us5-datadoghq.com | |
| https://example.comSSSSSSSSSSSSSSSSSSSSSSSSS | https://example.com | |
| https://chromewebstore.google.com/detail/claude/dngcpimnedloihjnnfngkgjoidhnaolf | https://chromewebstore.google.com/ | |
| https://github.com/syntax-tree/hast-util-to-jsx-runtime | https://github.com/uuidjs/uuid#getrandomvalues-not-supported | |
| https://support.claude.com/en/articles/12012173-getting-started-with-claude-for-chrome#h_91c6e5a1ee | https://claude.ai/upgrade?hide_free=true | |
| https://prosemirror.net/docs/guide/#generatable | https://support.anthropic.com/en/articles/8525154-claude-is-providing-incorrect-or-misleading-responses-what-s-going-on | |
| https://support.claude.com/en/articles/10023548-how-long-do-you-store-my-data | https://claude.ai/settings/connectors | |
| https://claude.ai/api/desktop/darwin/universal/dmg/latest/redirect | https://claude.ai/download | |
| https://claude.com/product/cowork | https://www.google.com/s2/favicons?domain= | |
| https://claude.ai/settings/usage | https://www.anthropic.com/legal/aup | |
| http://www.apache.org/licenses/LICENSE-2.0 | http://www.w3.org/1998/Math/MathML | |
| http://www.w3.org/1999/xhtml | http://www.w3.org/1999/xlink | |
| http://www.example.com | https://60bea3ee4ef1022e4035b23ba50f44d0@o1158394.ingest.us.sentry.io/4509876992278529 | |
| https://docs.honeycomb.io/getting-data-in/opentelemetry/node-distro/#sampling-without-the-honeycomb-sdk | https://feross.org/opensource | |
| https://tailwindcss.com | https://gmail.com | |
| https://www.anthropic.com/news | https://docs.datadoghq.com | |
| https://www.datadoghq-browser-agent.com | https://www.datad0g-browser-agent.com | |
| https://d3uc069fcn7uxw.cloudfront.net | https://d20xtzwzcl0ceb.cloudfront.net | |
| https://docs.google.com/forms/d/e/1FAIpQLSdLa1wTVkB2ml2abPI1FP9KiboOnp2N0c3aDmp5rWmaOybWwQ/viewform | https://claude.ai/oauth/authorize | |
| https://platform.claude.com/v1/oauth/token | https://claude.ai/chrome/installed | |
| https://react.dev/errors/ | http://www.w3.org/XML/1998/namespace | |
| https://formatjs.github.io/docs/tooling/babel-plugin | https://formatjs.github.io/docs/tooling/ts-transformer | |
| https://formatjs.github.io/docs/tooling/linter#enforce-id | https://formatjs.github.io/docs/getting-started/message-distribution | |
| https://formatjs.github.io/docs/react-intl#runtime-requirements | https://formatjs.github.io/docs/react-intl/api#intlshape | |
| https://docs.expo.dev/versions/latest/sdk/expo/#expofetch-api | https://github.com/anthropics/anthropic-sdk-typescript#streaming-responses | |
| https://github.com/anthropics/anthropic-sdk-typescript#long-requests | https://lodash.com/ | |
| https://openjsf.org/ | https://lodash.com/license | |
| http://underscorejs.org/LICENSE | https://npms.io/search?q=ponyfill. | |
| https://claude.com/form/anthropic-content-reporting | https://cdn.segment.com | |
| https://cdn.segment. | https://nextjs.org/docs/messages/public-next-folder-conflict | |
| https://nextjs.org/docs/messages/404-get-initial-props | https://nextjs.org/docs/messages/gssp-export | |
| https://nextjs.org/docs/messages/gssp-component-member | https://nextjs.org/docs/messages/non-standard-node-env | |
| https://nextjs.org/docs/messages/ssg-fallback-true-export | https://radix-ui.com/primitives/docs/components/ | |
| https://cdn.growthbook.io | https://nextjs.org/docs/messages/next-dynamic-api-wrong-context | |
| https://nextjs.org/docs/app/building-your-application/rendering/static-and-dynamic#dynamic-rendering | https://nextjs.org/docs/messages/dynamic-server-error | |
| https://nextjs.org/docs/messages/ppr-caught-error | https://nextjs.org/docs/messages/next-prerender-missing-suspense |
{ "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjU1XnLPoasGVmZU42K3h6S+sQhkogfcoLPbIcrWH5Oo8QoInBIugkew/7cWaEFySyQrkaEBe1fjeS/rlAqd3r778dKcTvDZcXmj0VVX0Fi1i8tnkarurceGKGdVxfkL7e30nwfgwoPxj3H8OQbsbxFcBWGVtcFekmdpiyaxwz6o4yXIWColfAxh9K2yToOZkoAS5GvgGvTexiCh1gYy++eFdk6C61mcFsyDdoGQtduhGEaX0zZ9uAW1jX4JTPmHV3kEFrZu/WVBl7Obw+Jk/osoHMdmghVNy6SCB8/6mcgmxkP9buPrNUZgYP6n0x5dqEJ2Ecww/lb1Zd4nQf4XGOwIDAQAB", "name": "Claude", "icons": { "128": "icon-128.png" }, "action": { "default_title": "Open Claude" }, "version": "1.0.58", "commands": { "toggle-side-panel": { "description": "Toggle Claude side panel", "suggested_key": { "mac": "Command+E", "default": "Ctrl+E" } } }, "background": { "type": "module", "service_worker": "service-worker-loader.js" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "Claude in Chrome (Beta)", "permissions": [ "sidePanel", "storage", "activeTab", "scripting", "debugger", "tabGroups", "tabs", "alarms", "notifications", "system.display", "webNavigation", "declarativeNetRequestWithHostAccess", "offscreen", "nativeMessaging", "unlimitedStorage", "downloads" ], "options_page": "options.html", "content_scripts": [ { "js": [ "assets/content-script.ts-Bwa5rY9t.js" ], "run_at": "document_end", "matches": [ "https://claude.ai/*", "https://*.claude.ai/*" ] }, { "js": [ "assets/accessibility-tree.js-D8KNCIWO.js" ], "run_at": "document_start", "matches": [ "<all_urls>" ], "all_frames": true }, { "js": [ "assets/agent-visual-indicator.js-Ct7LqXhp.js" ], "run_at": "document_idle", "matches": [ "<all_urls>" ], "all_frames": false } ], "host_permissions": [ "<all_urls>" ], "manifest_version": 3, "externally_connectable": { "matches": [ "https://claude.ai/*", "https://*.claude.ai/*" ] }, "minimum_chrome_version": "116", "content_security_policy": { "extension_pages": "script-src 'self'; object-src 'self'; connect-src 'self' https://api.anthropic.com wss://api.anthropic.com https://claude.ai https://platform.claude.com https://api.segment.io https://*.segment.com https://*.ingest.us.sentry.io https://api.honeycomb.io https://browser-intake-us5-datadoghq.com wss://bridge.claudeusercontent.com wss://bridge-staging.claudeusercontent.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:;" }, "web_accessible_resources": [ { "matches": [ "https://*.claude.ai/*", "https://claude.ai/*" ], "resources": [ "assets/content-script.ts-Bwa5rY9t.js" ], "use_dynamic_url": false }, { "matches": [ "<all_urls>" ], "resources": [ "assets/accessibility-tree.js-D8KNCIWO.js", "assets/agent-visual-indicator.js-Ct7LqXhp.js" ], "use_dynamic_url": false } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.