Is Briskine: Email templates for Gmail™ safe?

Medium risk

Briskine is medium risk. Using Briskine templates in Gmail or Outlook, the content script reads compose metadata (sender, to, cc, bcc, subject) and passes it to the sandboxed template renderer. Evidence did not show these fields sent to a network endpoint.

Briskinev8.1.1Chrome Web Store
45Risk
Who publishes it

Briskine SRL - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Briskine
Declared legal entity
Briskine SRL
Registered address
Bulevardul 1 DECEMBRIE 1918, Nr. 261, Ap. B2, Târgu Mureş, Mureș 540510, RO
Registered contact
Cristian-Ioan Colceriu

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Email metadata read for Gmail and Outlook templates

Using Briskine templates in Gmail or Outlook, the content script reads compose metadata (sender, to, cc, bcc, subject) and passes it to the sandboxed template renderer.

Evidence did not show these fields sent to a network endpoint.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You use a Briskine template while composing a Gmail or Outlook message.

The extension did this

The extension reads compose-page metadata and prepares it as template context.

The verified path covers Gmail and Outlook handlers for sender, recipients, copy fields, blind-copy fields, and subject.

02EvidenceFIELD TABLE
Compose metadata read from Gmail and Outlook pages
FieldValueWhy it matters
Sender account
Alex Chen <alex.chen@example.com>This can identify which mailbox or account is composing the message.
Recipients
Maya Patel <maya.patel@example.net>This reveals who the message is addressed to when the template is rendered.
Copy recipients
finance-team@example.orgThis can reveal additional people included in the message thread.
Blind-copy recipients
legal-review@example.orgThis can reveal recipients that are normally not visible to other message recipients.
Subject line
Quarterly renewal quoteThis describes the topic of the email being drafted.
03EvidenceCODE COMPARE
The code that does this

Gmail and Outlook handlers that read compose metadata

What it actually does
Deobfuscated Gmail data handlercontent/content.js
U("data", function({
  element: t
}) {
  if (!vo()) return;
  const e = {
    from: {},
    to: [],
    cc: [],
    bcc: [],
    subject: ""
  };
  if (io(t)) {
    const n = (document.title || "").split(" ").find(t => t.includes("@")) || "",
      r = Array.from(document.querySelectorAll("div")).reverse().find(t => t.innerText === n),
      i = r ? r.previousElementSibling : null,
      o = i ? i.innerText : "";
    e.from = st({
      name: o,
      email: n
    });
    const s = t.closest(go);
    if (s) {
      const t = xo(s);
      t && (e.from = wo(t.innerText)), ["to", "cc", "bcc"].forEach(t => {
        e[t] = Array.from(s.querySelectorAll(`input[name=${t}], [name=${t}] [role=option]`)).map(t => {
          if (t.value) return wo(t.value);
          const e = t.getAttribute("data-hovercard-id");
          return e ? st({
            email: e,
            name: t.getAttribute("data-name")
          }) : {}
        })
      });
      const n = s.querySelector("input[name=subjectbox]");
      n && (e.subject = (n.value || "").replace(/^Re: /, ""))
    }
  }
  return e
})
Deobfuscated Outlook data handlercontent/content.js
U("data", function({
  element: t
}) {
  if (Io()) return async function({
    element: t
  }) {
    await So(t);
    const e = {
      from: {},
      to: [],
      cc: [],
      bcc: [],
      subject: ""
    };
    if (!t) return e;
    const n = t.ownerDocument,
      r = n.querySelector("#O365_MainLink_Me > div > div:nth-child(1)");
    let i = "";
    r && (i = r.textContent);
    let o = "";
    const s = n.querySelector("[role=complementary] [aria-haspopup=menu] + * [aria-haspopup=dialog]");
    s && (o = s.innerText), e.from = st({
      name: i,
      email: o
    });
    const a = t;
    var c = Lo(a);
    c && Do(e.to, c);
    var l = _o(a);
    l && Do(e.cc, l);
    var u = Fo(a);
    u && Do(e.bcc, u);
    const h = Oo(a);
    return h && (e.subject = h.value), e
  }({
    element: t
  })
})
04EvidenceCODE COMPARE
The code that does this

Template context is sent to the sandbox renderer

What it actually does
Deobfuscated context rendering helpercontent/content.js
async function At(t = "", e = {}) {
  let n;
  try {
    n = (0, q.parse)(t)
  } catch (t) {
    return `<pre>${t.message||t}</pre>`
  }
  const r = lt(n),
    i = await async function(t = {}) {
      const e = structuredClone(t);
      return ht.forEach(t => {
        const n = Array.isArray(e[t] || []) ? e[t] : [e[t]];
        e[t] = function(t = []) {
          const e = [];
          return t.length && (t.forEach(t => e.push(st(t))), Object.entries(e[0]).forEach(([t, n]) => e[t] = n)), e
        }(n)
      }), e.account = st(await async function(t = {}) {
        let e = {};
        try {
          const t = await L();
          e = {
            name: t.full_name,
            email: t.email
          }
        } catch {}
        return ut(e, t)
      }(e.account)), e.from = st(ut(e.account, e.from)), e
    }(e);
  let o = [];
  return r.partials && (o = (await _()).filter(e => e.shortcut?.trim?.() && e.body !== t).map(t => ({
    shortcut: t.shortcut,
    body: t.body
  }))), async function(t = "", e = {}, n = []) {
    return nt ? it(t, e, n) : (nt = document.createElement(rt), new Promise(r => {
      nt.onload = () => {
        it(t, e, n).then(r)
      }, document.documentElement.appendChild(nt)
    }))
  }(n, i, o)
}
Deobfuscated sandbox request wrappercontent/content.js
function it(t, e, n) {
  return et("briskine-template-compile", {
    template: t,
    context: e,
    partials: n
  })
}
Updated 30 September 2026lmcngpkjkplipamgflhioabnhnopeabf