CRX aminer
Extension icon

NoteKitLM for NotebookLM: Better Workflow for Books, Web & ChatGPT Research

Version 1.4.0 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 5.0 ★ (4 ratings)
Users: 404

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has very limited user adoption with only 404 users and just 4 reviews, despite a perfect 5.0 rating. The small user base makes it difficult to assess real-world reliability. The extension appears to integrate with popular AI platforms (ChatGPT, Claude, Gemini) and Google's NotebookLM, which suggests legitimate functionality for research workflows. However, the lack of developer information and company details raises transparency concerns.

Concerns:

The extension requests extremely broad permissions that far exceed what would be necessary for a research workflow tool. The debugger permission is particularly concerning as it allows manipulation of other extensions and browser debugging capabilities. The <all_urls> host permission combined with broad content script injection creates significant privacy and security risks. The downloads permission could enable unauthorized file downloads, while webNavigation tracking capabilities allow comprehensive browsing surveillance. These permissions collectively create potential for data theft, credential harvesting, and extensive user tracking across all websites.

Recommendations:

Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with no saved passwords or sensitive data. Consider alternative research tools with more limited permissions. Monitor your browser's download history and network activity if using this extension. The broad permissions suggest either poor security practices or potentially malicious intent - the legitimate functionality likely doesn't require such extensive access.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://notebooklm.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.