Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeGrok AI
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Extension extracts full page content (URL, title, visible text) and transmits it to third-party easytool.dev servers via iframe postMessage
  2. 02Extension's postMessage handler trusts all messages from easytool.dev, enabling the third-party server to request page content extraction and chrome.storage access
  3. 03Extension loads all UI from third-party easytool.dev domains not affiliated with the named AI services (Grok, ChatGPT, Perplexity, etc.)
OTHER EXTENSIONS

Is Grok AI safe?

Medium risk

No summary available.

v3.1.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026hafhkoalnlpoifpidohfjlmeemfifndi

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact