Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeChatGPT Image Auto
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Both background.js and sidepanel.js monkey-patch chrome.scripting.executeScript to a no-op when the code detects it is running in a non-minified (i.e. analysis/debugger) context, suppressing all scripting activity and defeating dynamic analysis.
  2. 02Extension injects scripts into chatgpt.com tabs that fetch the ChatGPT session access token and use it to read conversation data and download generated images via private backend API endpoints.
  3. 03Transmits user-supplied image prompts and base64-encoded reference images to Google Whisk API endpoints
+2 more findings locked
OTHER EXTENSIONS

Is ChatGPT Image Auto safe?

Medium risk

No summary available.

duckmartiansv8.4.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026gedfnhdibkfgacmkbjgpfjihacalnlpn

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact