This extension shows critical risk indicators. It requests highly sensitive permissions combined with suspicious code patterns. Proceed with extreme caution.
Based on 20 permissions including high-risk ones, 218 code findings, 3 dangerous combinations.
Extension has cookie access and sends data to external servers — potential session token theft.
Extension tracks open tabs and communicates with external servers — potential browsing surveillance.
Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.
2 libraries detected
object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.
Resolved from __MSG_* i18n placeholders:
Name: HARPA AI: Web Automation with ChatGPT, Claude, Gemini, Grok
Description: Free AI sidebar with ChatGPT, Claude, Gemini & DeepSeek. 100+ commands to automate, monitor prices, summarize & write.
JavaScript files are accessible to ALL websites. Any page can load and interact with these scripts, enabling web→extension attacks.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Content script runs at document_start in ALL frames on ALL URLs. This gives the extension deep access to every page load, including iframes.
283 indicators of compromise found