Codeastra — Agent Data Blindness

ID: mnemfifffhahlkddfjddghlalonkphbi

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Active
Version
1.5.0
Size
0.03 MB
Rating
0.0/5
Reviews
0
Users
0
Type
Extension
Updated
Apr 28, 2026
Category
Privacy & security
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
https://codeastra.dev/View Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Total Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Total Users
0

Auto-tokenize PHI/PII in 50+ apps & AI chats (ChatGPT, Claude, Gemini) — paste & file uploads protected.

Codeastra protects sensitive data , patient SSNs, medical record numbers, financial information, personal identifiers before it ever leaves your browser. How it works: When you compose an email in Gmail containing sensitive data and click Send, Codeastra intercepts it, replaces every sensitive value with a secure vault token, and then sends the email. The real values never reach Gmail's servers. When a colleague from the same workspace opens the email, all tokens are automatically resolved back to real values inline. No copy-paste. No manual steps. What it protects: SSN, MRN, credit card numbers, email addresses, phone numbers, dates of birth, employee IDs, case references, financial amounts, and more. Who it is for: Healthcare teams sharing patient referrals. Legal teams sharing case details. HR teams sharing payroll data. Any team that sends sensitive information over email. Security model: Real values never travel in email. Only tokens do. Tokens are stored in your encrypted Codeastra vault. Only users from the same workspace with a valid API key can resolve them. Expired tokens and wrong-workspace keys are always blocked. Requirements: A free Codeastra API key from app.codeastra.dev

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
https://mail.google.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://outlook.live.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://outlook.office.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://outlook.office365.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://app.slack.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.slack.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://teams.microsoft.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://teams.live.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://discord.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://web.whatsapp.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://web.telegram.org/*
Host
Medium
Host permission — access limited to this URL pattern.
https://www.linkedin.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.lightning.force.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.salesforce.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.zendesk.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.freshdesk.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.intercom.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://app.hubspot.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://www.notion.so/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.atlassian.net/*
Host
Medium
Host permission — access limited to this URL pattern.
https://app.asana.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://trello.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://app.monday.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://app.clickup.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://linear.app/*
Host
Medium
Host permission — access limited to this URL pattern.
https://github.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://gitlab.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://bitbucket.org/*
Host
Medium
Host permission — access limited to this URL pattern.
https://docs.google.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://drive.google.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://keep.google.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://onedrive.live.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.sharepoint.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://www.onenote.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://www.dropbox.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://paper.dropbox.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://app.box.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://www.evernote.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://airtable.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://coda.io/*
Host
Medium
Host permission — access limited to this URL pattern.
https://quip.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.quip.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://app.smartsheet.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://chatgpt.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://chat.openai.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://claude.ai/*
Host
Medium
Host permission — access limited to this URL pattern.
https://gemini.google.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://www.perplexity.ai/*
Host
Medium
Host permission — access limited to this URL pattern.
https://copilot.microsoft.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://copilot.cloud.microsoft/*
Host
Medium
Host permission — access limited to this URL pattern.
https://pi.ai/*
Host
Medium
Host permission — access limited to this URL pattern.
https://character.ai/*
Host
Medium
Host permission — access limited to this URL pattern.
https://www.jasper.ai/*
Host
Medium
Host permission — access limited to this URL pattern.
https://app.copy.ai/*
Host
Medium
Host permission — access limited to this URL pattern.
https://you.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://www.phind.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://huggingface.co/chat/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.codeastra.dev/*
Host
Medium
Host permission — access limited to this URL pattern.
http://localhost/*
Host
Medium
Host permission — access limited to this URL pattern.
Access to Sensitive Domains
Risk Factor
Medium
This extension requests access to sensitive domains: https://mail.google.com/*, https://outlook.live.com/*, https://outlook.office.com/*, https://outlook.office365.com/*, https://www.linkedin.com/*, https://*.lightning.force.com/*, https://app.hubspot.com/*, https://github.com/*, https://gitlab.com/*, https://bitbucket.org/*, https://docs.google.com/*, https://drive.google.com/*, https://keep.google.com/*, https://gemini.google.com/*, https://huggingface.co/chat/*
URLs
1
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

app.codeastra.dev-https://app.codeastra.dev

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.5.0
Latest
0.03 MB
Benign
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.