Local capability audit for Chrome extensions

Know which extensions can reach your AI workspace

AI Chat Shield reviews installed-extension metadata, declared permissions, host access, and install-source signals. It never reads your chat content or browsing history.

Add to Chrome - Free See what it checks
ChatGPT Claude Gemini Copilot DeepSeek Perplexity
CS AI Chat Shield
Review needed
Extension access reviewDeclared capabilities, explained without a black-box verdict.
61/100
AI
AI-site host accessDirect AI-domain access or broad all-sites coverage
Review
WEB
Request and browsing capabilitiesRequest control, cookies, history, downloads, and related permissions
Explained
SRC
Install-source signalNormal, development, sideloaded, or administrator-installed
Local

Illustrative report. Scores measure declared capability exposure, not confirmed malicious behavior.

Browser extensions can inherit the trust you give your AI tools

Recent research shows how legitimate-looking extensions and later updates can expose sensitive AI conversations. Store placement and ratings are useful context, not proof of safety.

8M+
Koi Security research · December 2025
Privacy extensions collected complete AI conversations

Koi documented AI-chat collection across eight Chrome and Edge extensions with more than eight million combined users.

~900K
Lookalike AI assistants harvested chat histories

Microsoft reported malicious Chromium extensions that copied familiar AI-assistant branding while collecting URLs and ChatGPT or DeepSeek content.

1 update
Koi Security timeline · July 2025 onward
An ordinary update can change the permission story

The Urban VPN collection code arrived in a later version. Rechecking access after extension changes matters even when the original install looked reasonable.

A capability review, not a malware verdict

Chrome exposes another extension's declared metadata and permissions, not its private source code or live traffic. AI Chat Shield turns the available evidence into an explainable review queue.

Capability Scan

Review declared access

Each installed extension receives a transparent exposure score based on five signals the browser makes available.

  • Direct AI-domain access versus broad all-sites access
  • Request control, cookies, history, downloads, and related permissions
  • Page modification, native messaging, debugger, and identity capabilities
  • Enabled state and Chrome install-source signal
Session Awareness

Put the scan in context

On supported AI sites, the toolbar cross-references the current page with the latest local capability scan.

  • URL-pattern detection for supported AI platforms only
  • Toolbar status based on enabled extensions and the latest scan
  • Automatic rescans after install, enable, disable, or removal events
  • Optional Pro activity history stored in local extension storage

Know the limit: AI Chat Shield cannot see another extension's private code, inspect its DOM activity, observe its network traffic, or certify it as safe. A high score means “review this access.” A low score is not a guarantee.

Your conversations stay out of the scan

The free capability scan and activity data stay in local extension storage. The optional Pro activation flow has one narrow server boundary: the subscription email you choose to enter.

Local Scan Data

Installed-extension metadata, exposure scores, settings, and activity history remain in local extension storage.

No Chat Content or History

The extension does not read prompts, responses, page content, full URLs, or browsing history.

No Telemetry

No product analytics, advertising, or scan-result uploads are built into the consumer extension.

Pro Validation Boundary

If you activate Pro, the entered email is sent to our validator. The returned status and email are stored locally, not in Chrome Sync.

Review access before the next sensitive prompt

The capability scan is free and needs no account. Pro activity history is optional.

Add to Chrome - Free