CRX aminer
Extension icon

Grok Automation - Auto Grok on Grok.com

Version 1.4.2.0 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Developer: kylenguyen.me
Rating: 4.1 ★ (84 ratings)
Users: 100,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a substantial user base of 100,000 users and maintains a decent 4.1-star rating from 84 reviews, suggesting general user satisfaction. However, the developer identity "kylenguyen.me" appears to be an individual rather than an established company, which reduces institutional trust. The extension targets Grok.com specifically, which is a legitimate AI platform, and the automation functionality aligns with its stated purpose.

Concerns:

The extension requests several powerful permissions that create significant security risks. The tabs permission allows comprehensive browser tab manipulation and information access, while the downloads permission enables file downloads and access to download history - both capabilities that extend well beyond basic automation needs for Grok.com. The broad host permissions covering all Grok.com subdomains create potential for data interception across the entire platform. The combination of these permissions could enable malicious activities like data theft, unauthorized downloads, or browsing surveillance.

Recommendations:

Given the high-risk permission set, consider running this extension in a separate Chrome profile to isolate potential security impacts. Before installation, verify that the automation features truly require such extensive permissions. Monitor the extension's behavior closely, particularly any unexpected download activity or tab manipulation. Consider whether manual interaction with Grok.com might be safer than automated access through this extension. Regularly review the extension's permissions and remove it if you notice any suspicious activity.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.