CRX aminer
Extension icon

NotebookLM Importer

Version 2.0.5 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 4.9 ★
Users: 97

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited adoption with only 97 users, which raises concerns about its maturity and community vetting. While it maintains a high 4.9-star rating, the small user base makes this less meaningful. The lack of visible author and developer information is concerning for transparency and accountability. The extension targets NotebookLM, Google's AI note-taking service, which suggests legitimate functionality but also involves handling potentially sensitive user data.

Concerns:

The extension requests unnecessarily broad permissions for its stated purpose. The cookies permission is particularly concerning as it allows access to authentication tokens and session data across Google domains. The tabs permission enables monitoring and manipulation of all browser tabs, which exceeds what's needed for a simple importer tool. The broad host permissions to all Google domains create excessive attack surface. The combination of these permissions could enable data exfiltration, session hijacking, or unauthorized access to Google services beyond NotebookLM.

Recommendations:

Given the high risk level and limited user base, consider running this extension in a separate Chrome profile dedicated to NotebookLM work only. Before installation, verify the extension's legitimacy through official channels or trusted sources. Monitor your Google account activity for any unusual behavior after installation. Consider alternative methods for importing data to NotebookLM that don't require such broad permissions. If you must use this extension, regularly review your Google account's security settings and connected applications.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://notebooklm.google.com/*, https://*.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.