CRX aminer

Starting analysis...

Extension icon

Do Browser: AI Browser Agent

Version 3.1.25 View in Chrome Web Store

Last scanned: 19 days ago | force re-scan

Extension Details

Developer: dobrowser.io
Rating: 3.4 ★ (58 ratings)
Users: 10,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has a moderate user base of 10,000 users but concerning trust indicators including a below-average rating of 3.4 stars from only 58 reviews, suggesting limited user satisfaction or engagement. The developer domain dobrowser.io appears to be purpose-built for this extension, which provides less established credibility compared to well-known companies.
Concerns: The extension exhibits multiple high-risk characteristics that are concerning for an AI browser agent. The debugger permission is particularly alarming as it allows manipulation of other extensions and browser debugging capabilities, which far exceeds typical needs for an AI assistant. The combination of broad host permissions with tabs access creates extensive surveillance capabilities across websites. The unsafe-eval CSP policy allows dynamic JavaScript execution, creating potential attack vectors for malicious code injection. The scripting permission combined with these other capabilities creates a powerful toolkit that could be misused for data harvesting or malicious activities.
Recommendations: Given the critical risk level, avoid installing this extension on your primary browser profile. If you must test it, create a dedicated Chrome profile with no sensitive data or important accounts logged in. Consider alternative AI browser assistants from more established developers with better security practices. Monitor your browsing behavior closely if installed, and remove immediately if you notice any suspicious activity or performance issues.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe JavaScript Evaluation
This extension's Content Security Policy allows 'unsafe-eval', which permits dynamic JavaScript code execution using eval() and similar functions. This is a significant security risk as it could allow execution of malicious code.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.