Superpowers for ChatgptSecurity Analysis

Chromev1.1.5MV3February 16, 2026 at 03:37 PM
8.2CRITICAL
8.2 CRITICAL

This extension shows critical risk indicators. It requests highly sensitive permissions combined with suspicious code patterns. Proceed with extreme caution.

Based on 6 permissions including high-risk ones, 19 code findings.

Permissions
9.5/10
Code
10.0/10
Combinations
0.0/10
Manifest/CSP
4.5/10

Permissions(6 analyzed)

Code Findings(11 patterns, 19 total)

Content Security Policy

No CSP Defined(1 issue)
MEDIUM
N/ANo CSP defined

This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.

Manifest Analysis(1 finding)

Resolved from __MSG_* i18n placeholders:

Name: Superpowers for Chatgpt

Description: The ultimate browser extension for accessing Chatgpt

MEDIUM
web_accessible_resources.matchesOverly broad match patterns

Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.

External Domains(7)

bit.lychatgpt.comgithub.comreactjs.orgredux.js.orgwebpack.js.orgwww.google-analytics.com

Indicators of Compromise

2 indicators of compromise found

File Statistics

83
Total Files
3
JS Files
3.8 MB
Total Size

Other Scanned Extensions