CRX aminer
Extension icon

NotebookLM Importer - Web & YouTube

Version 1.0.2 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 4.9 ★
Users: 62

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited adoption with only 62 users, which raises concerns about its maturity and community vetting. While it maintains a high 4.9 rating, the small user base makes this less meaningful. The lack of visible developer information reduces transparency and accountability. The extension targets NotebookLM integration, which suggests legitimate functionality, but the implementation approach raises security concerns.

Concerns:

The identity permission combined with identity.email access creates significant privacy risks, allowing the extension to access your Google account information. The broad host permissions (https://*/*) grant access to all websites, which is excessive for an extension that should primarily interact with NotebookLM and specific content sources. This combination of identity access and universal website permissions creates a dangerous attack surface where the extension could potentially harvest personal data across all your browsing activities.

The storage permission, while necessary for functionality, adds another data collection vector when combined with the other permissions.

Recommendations:

Given the high-risk permission combination and low user adoption, consider running this extension in a separate Chrome profile isolated from your main browsing activities. Only use it when specifically needed for NotebookLM tasks. Monitor your Google account activity for any unusual access patterns. Consider waiting for the extension to mature and gain more users before trusting it with sensitive permissions, or look for alternative solutions with more restrictive permissions.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://notebooklm.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.