Starting analysis...
The extension is developed by Anthropic, a reputable AI company known for Claude AI assistant, which adds credibility. However, the relatively low rating of 2.9 out of 5 stars from 230 reviews is concerning and suggests user dissatisfaction or potential issues. The substantial user base of 500,000 indicates widespread adoption, but the poor rating undermines confidence in the extension's quality or user experience.
The extension requests an excessive number of high-risk permissions that seem disproportionate for an AI assistant tool. The debugger permission is particularly alarming as it allows manipulation of other extensions and browser debugging capabilities. The combination of broad host permissions with content script injection across all websites creates significant privacy and security risks. The tabs and webNavigation permissions enable comprehensive browsing activity monitoring, while the downloads permission could facilitate unauthorized file access. The nativeMessaging capability allows communication with external applications, expanding the attack surface.
Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with minimal sensitive data and browsing activity. Consider using the official Claude web interface at claude.ai instead of this extension. Monitor your browser's performance and security closely if installed, and regularly review what data the extension might be accessing through Chrome's extension management settings.
| https://github.com/jnordberg/gif.js | http://www.w3.org/2000/svg | |
| https://clients2.google.com/service/update2/crx | https://claude.ai/ | |
| https://api.anthropic.com | https://claude.ai | |
| https://console.anthropic.com | https://statsig.com | |
| https://api.statsig.com | https://featuregates.org | |
| https://statsigapi.net | https://events.statsigapi.net | |
| https://api.statsigcdn.com | https://featureassets.org | |
| https://assetsconfigcdn.org | https://prodregistryv2.org | |
| https://cloudflare-dns.com | https://beyondwickedmapping.org | |
| https://api.segment.io | https://api.honeycomb.io | |
| https://example.comSSSSSSSSSSSSSSSSSSSSSSSSS | https://example.com | |
| https://github.com/syntax-tree/hast-util-to-jsx-runtime | https://github.com/uuidjs/uuid#getrandomvalues-not-supported | |
| https://nextjs.org/docs/messages/invalid-images-config | https://nextjs.org/docs/messages/next-image-missing-loader | |
| https://slack.mcp.ant.dev/sse | https://mcp-server-gcal-586545259222.us-central1.run.app/sse | |
| https://mcp-server-gcal-586545259222.us-central1.run.app/mcp | https://gcal.mcp.claude.com/mcp | |
| https://gcal.mcp.staging.ant.dev/mcp | https://mcp-server-gmail-110131437935.us-central1.run.app/sse | |
| https://mcp-server-gmail-110131437935.us-central1.run.app/mcp | https://gmail.mcp.claude.com/mcp | |
| https://gmail.mcp.staging.ant.dev/mcp | https://api.anthropic.com/mcp/gdrive/sse | |
| https://api.anthropic.com/mcp/gdrive/mcp | https://mcp-server-gdrive-532483229523.us-central1.run.app/sse | |
| https://microsoft365.mcp.claude.com/mcp | https://www.microsoft.com/microsoft-365 | |
| https://www.google.com/s2/favicons | https://www.gstatic.com | |
| https://t0.gstatic.com | https://gmail.mcp.claude.com/sse | |
| https://gmail.mcp.staging.ant.dev/sse | https://gdrive.mcp.claude.com/mcp | |
| https://gdrive.mcp.claude.com/sse | https://gcal.mcp.claude.com/sse | |
| https://gcal.mcp.staging.ant.dev/sse | https://slack.mcp.ant.dev/mcp | |
| https://microsoft365.mcp.claude.com/sse | https://www.google.com/s2/favicons?domain= | |
| https://claude.ai/settings/integrations | https://feross.org/opensource | |
| https://github.com/indutny/elliptic/issues | https://github.com/indutny/elliptic | |
| https://github.com/browserify/crypto-browserify | https://raw.githubusercontent.com/ajv-validator/ajv/master/lib/refs/data.json# | |
| http://json-schema.org/draft-07/schema# | https://github.com/ajv-validator/ajv/blob/master/lib/definition_schema.js | |
| http://json-schema.org/draft-07/schema | http://json-schema.org/schema | |
| https://react.dev/errors/ | http://www.w3.org/1998/Math/MathML | |
| http://www.w3.org/1999/xlink | http://www.w3.org/XML/1998/namespace | |
| https://formatjs.github.io/docs/tooling/babel-plugin | https://formatjs.github.io/docs/tooling/ts-transformer | |
| https://formatjs.github.io/docs/tooling/linter#enforce-id | https://formatjs.github.io/docs/getting-started/message-distribution | |
| https://formatjs.github.io/docs/react-intl#runtime-requirements | https://formatjs.github.io/docs/react-intl/api#intlshape | |
| https://prodregistryv2.org/v1 | https://featureassets.org/v1 | |
| https://api.statsigcdn.com/v1 | https://statsigapi.net/v1/sdk_exception | |
| https://cloudflare-dns.com/dns-query | https://docs.statsig.com/client/javascript-sdk/#typed-getters | |
| https://radix-ui.com/primitives/docs/components/ | https://nextjs.org/docs/messages/public-next-folder-conflict |
{ "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjU1XnLPoasGVmZU42K3h6S+sQhkogfcoLPbIcrWH5Oo8QoInBIugkew/7cWaEFySyQrkaEBe1fjeS/rlAqd3r778dKcTvDZcXmj0VVX0Fi1i8tnkarurceGKGdVxfkL7e30nwfgwoPxj3H8OQbsbxFcBWGVtcFekmdpiyaxwz6o4yXIWColfAxh9K2yToOZkoAS5GvgGvTexiCh1gYy++eFdk6C61mcFsyDdoGQtduhGEaX0zZ9uAW1jX4JTPmHV3kEFrZu/WVBl7Obw+Jk/osoHMdmghVNy6SCB8/6mcgmxkP9buPrNUZgYP6n0x5dqEJ2Ecww/lb1Zd4nQf4XGOwIDAQAB", "name": "Claude", "icons": { "128": "icon-128.png" }, "action": { "default_title": "Open Claude" }, "version": "1.0.36", "commands": { "toggle-side-panel": { "description": "Toggle Claude side panel", "suggested_key": { "mac": "Command+E", "default": "Ctrl+E" } } }, "background": { "type": "module", "service_worker": "service-worker-loader.js" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "Claude for Chrome (Beta)", "permissions": [ "sidePanel", "storage", "activeTab", "scripting", "debugger", "tabGroups", "tabs", "alarms", "notifications", "system.display", "webNavigation", "declarativeNetRequestWithHostAccess", "offscreen", "nativeMessaging", "unlimitedStorage", "downloads" ], "options_page": "options.html", "content_scripts": [ { "js": [ "assets/content-script.ts-Bwa5rY9t.js" ], "run_at": "document_end", "matches": [ "https://claude.ai/*", "https://*.claude.ai/*" ] }, { "js": [ "assets/accessibility-tree.js-D39zjmMD.js" ], "run_at": "document_start", "matches": [ "<all_urls>" ], "all_frames": true }, { "js": [ "assets/agent-visual-indicator.js-Ct7LqXhp.js" ], "run_at": "document_idle", "matches": [ "<all_urls>" ], "all_frames": false } ], "host_permissions": [ "<all_urls>" ], "manifest_version": 3, "externally_connectable": { "matches": [ "https://claude.ai/*", "https://*.claude.ai/*" ] }, "content_security_policy": { "extension_pages": "script-src 'self'; object-src 'self'; connect-src 'self' https://api.anthropic.com wss://api.anthropic.com https://claude.ai https://console.anthropic.com https://statsig.com https://*.statsig.com https://api.statsig.com https://featuregates.org https://statsigapi.net https://events.statsigapi.net https://api.statsigcdn.com https://featureassets.org https://assetsconfigcdn.org https://prodregistryv2.org https://cloudflare-dns.com https://beyondwickedmapping.org https://api.segment.io https://*.segment.com https://*.ingest.us.sentry.io https://api.honeycomb.io; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:;" }, "web_accessible_resources": [ { "matches": [ "https://*.claude.ai/*", "https://claude.ai/*" ], "resources": [ "assets/content-script.ts-Bwa5rY9t.js" ], "use_dynamic_url": false }, { "matches": [ "<all_urls>" ], "resources": [ "assets/accessibility-tree.js-D39zjmMD.js", "assets/agent-visual-indicator.js-Ct7LqXhp.js" ], "use_dynamic_url": false } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.