This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.
This extension shows some risk signals that are common in legitimate extensions but worth reviewing. Check the details below.
Based on 8 permissions including high-risk ones, 112 code findings, 1 dangerous combination.
Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.
2 libraries detected
This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.
Resolved from __MSG_* i18n placeholders:
Name: Monica: All-In-One AI Assist & Smartest AI Agent
Description: One stop AI Assistant with GPT, Claude, Gemini: Chat, Write, Translate, Search, Summarize, image generator, video generation
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
JavaScript files are accessible to ALL websites. Any page can load and interact with these scripts, enabling web→extension attacks.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Extension accepts messages from 3 external pattern(s). Verify these are trusted origins.
Content script matches <all_urls>, executing on every website the user visits.
16 indicators of compromise found