| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact• 10% increase: Early script execution enables pre-emptive content manipulation |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| https://chatgpt.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://chat.openai.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://claude.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://anthropic.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://gemini.google.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://perplexity.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://www.perplexity.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://copilot.microsoft.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://meta.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://www.meta.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://lovable.dev/* | Host | | Host permission — access limited to this URL pattern. |
| https://cursor.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://github.com/copilot/* | Host | | Host permission — access limited to this URL pattern. |
| https://chat.deepseek.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://grok.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://chat.mistral.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://poe.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://openrouter.ai/chat/* | Host | | Host permission — access limited to this URL pattern. |
| https://bolt.new/* | Host | | Host permission — access limited to this URL pattern. |
| https://v0.dev/* | Host | | Host permission — access limited to this URL pattern. |
| https://v0.app/* | Host | | Host permission — access limited to this URL pattern. |
| https://replit.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://sourcegraph.com/cody/* | Host | | Host permission — access limited to this URL pattern. |
| https://windsurf.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://chat.qwen.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://doubao.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://kimi.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://yuanbao.tencent.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://chatglm.cn/* | Host | | Host permission — access limited to this URL pattern. |
| https://yiyan.baidu.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://notebooklm.google.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://huggingface.co/chat/* | Host | | Host permission — access limited to this URL pattern. |
| https://lmarena.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://app.grammarly.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://notion.so/* | Host | | Host permission — access limited to this URL pattern. |
| https://app.jasper.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://manus.im/* | Host | | Host permission — access limited to this URL pattern. |
| https://app.devin.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://midjourney.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://runwayml.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://api.highflame.ai/* | Host | | Host permission — access limited to this URL pattern. |
| https://studio.highflame.ai/* | Host | | Host permission — access limited to this URL pattern. |
| Access to Sensitive Domains | Risk Factor | | This extension requests access to sensitive domains: https://gemini.google.com/*, https://github.com/copilot/*, https://notebooklm.google.com/*, https://huggingface.co/chat/* |
| Early Content Script Execution | Risk Factor | | This extension runs content scripts at document_start. |
| alarms | Permission | | This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data. |