Is SAP Build Process Automation extension Chrome safe?

Clean risk

SAP Build Process Automation extension captures page content, cookies, and screenshots and sends them to the local SAP desktop agent.

On command from the locally installed SAP Build Process Automation desktop agent, the extension reads page metadata including the full URL, document title, cookies, and DOM content from any open tab, and captures visible-tab screenshots as base64-encoded PNG images. It also injects keystrokes into browser tabs using the Chrome Debugger API. All collected data is sent exclusively to the locally running SAP broker process via a named native messaging port.

SAP SEv3.31.6Chrome Web Store
0Risk
Who publishes it

SAP - 6 other listings from the same operator, 2 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
SAP SE
Declared legal entity
SAP
Registered address
Dietmar-Hopp-Allee 16, Walldorf 69190, DE

Same operator - 1 listing

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.31.6. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls> and 1 more

  • Attach to pages with the browser's debugger, which can read and rewrite anything on them

    debugger

  • See the address and title of every tab you have open

    tabs

  • Keep running in the background while your browser is open

    background

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Run its own code inside the pages you visit

    scripting

  • Act on the current tab, but only after you click the extension

    activeTab

  • See, disable and uninstall your other extensions, including your security ones

    management

  • Store data in your browser

    storage

app.window

Where it sends data

Destinations our analysis observed CxAppChrome contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • contextor.chrome.extension.broker.messaging (local SAP native host)

    CxAppChrome sends data to contextor.chrome.extension.broker.messaging (local SAP native host). Named as a recipient in this extension's own analysis.

Updated 30 September 2026dlnhkapcpdnenaomhgpmkplleeahdjje