Is Grok AI safe?
Grok AI is medium risk. When the page-content feature is used after permission is granted, Grok AI collects the active page URL, title, and visible text. That page content is forwarded through its iframe messaging flow to grok-ai.easytool.dev.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Grok AI sends page URL, title, and visible text to easytool.dev.
When the page-content feature is used after permission is granted, Grok AI collects the active page URL, title, and visible text.
That page content is forwarded through its iframe messaging flow to grok-ai.easytool.dev.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-200
- Source
- Dynamic sandbox
The user takes the required action for the page-content feature.
The extension extracts the active page URL, title, and visible text, then forwards them to the easytool.dev iframe.
- Active page URLhttps://example.com/article (illustrative)
Shows the exact page open in the active browser tab.
- Page titleExample Article Title (illustrative)
Provides context about the page being viewed.
- Visible page textVisible paragraph text from the current page (illustrative)
Includes readable text from the page, which may contain sensitive page content.
Dynamic analysis confirmed the code path from page-content request to iframe forwarding; an earlier run could not complete the interaction while grok-ai.easytool.dev returned an unavailable-service response.
Grok AI's chat interface runs on easytool.dev, not X.ai or Grok.
Grok AI is branded after xAI's Grok, but every surface loads from an iframe at grok-ai.easytool.dev, unrelated to X.ai.
The code ships a map of five sibling easytool.dev subdomains for other brands.
Testing saw only that domain, never x.ai.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-829
- Source
- Dynamic sandbox
The user installs the extension expecting AI chat branded as Grok.
The extension routes the welcome page, side panel, and full-screen chat through an iframe pointed at grok-ai.easytool.dev, a domain not owned by X.ai or Grok.
Hardcoded product map resolving 'grok-ai' to the easytool.dev iframe
const p = { "chatgpt-5": { name: "chatgpt-5", iframeUrl: "https://chatgpt-5.easytool.dev" }, "grok-ai": { name: "grok-ai", iframeUrl: "https://grok-ai.easytool.dev" }, "grok-4": { name: "grok-4", iframeUrl: "https://grok-3.easytool.dev" }, "deepseek-ai": { name: "deepseek-ai", iframeUrl: "https://deepseek-ai.easytool.dev" }, "perplexity-ai": { name: "perplexity-ai", iframeUrl: "https://perplexity-ai.easytool.dev" }, "gemini-2": { name: "gemini-2", iframeUrl: "https://gemini-2.easytool.dev" } }, i = (e => { const t = p[e]; if (!t) throw new Error(`Unknown product: ${e}. Available products: ${Object.keys(p).join(", ")}`); return { name: t.name, iframeUrl: t.iframeUrl, buildDir: `build/${t.name}` } })("grok-ai").iframeUrl, S = { iframeUrls: { welcomePage: i + "/welcome-page?ref=ext", sidepanelPage: i + "/en/new-chat?ref=ext&sidepanel=true", chatPage: i + "/en/new-chat?ref=ext&fullscreen=true" }, uninstallUrl: i + "/uninstall-page?ref=ext&d=" + new Date().getTime(), trustedOrigin: new URL(i).origin, blockedProtocols: ["chrome:", "edge:", "about:", "devtools:", "chrome-extension:", "chrome-error:", "moz-extension:", "view-source:", "data:", "file:"], blockedHosts: ["chrome.google.com"] },Observed during dynamic analysis: opening the side panel and the welcome page both loaded a cross-origin iframe from grok-ai.easytool.dev. No request in the session reached x.ai, grok.com, or api.openai.com.
- grok-ai.easytool.dev
Active build for this extension (named 'Grok AI'). Not owned by X.ai.
- chatgpt-5.easytool.dev
Configured for a ChatGPT-branded build using the same product map. Not owned by OpenAI.
- grok-3.easytool.dev
Configured for a build labeled 'grok-4' internally. Not owned by X.ai.
- deepseek-ai.easytool.dev
Configured for a DeepSeek-branded build. Not owned by DeepSeek.
- perplexity-ai.easytool.dev
Configured for a Perplexity-branded build. Not owned by Perplexity AI.
- gemini-2.easytool.dev
Configured for a Gemini-branded build. Not owned by Google.
Grok AI iframe can request page content and extension storage.
Grok AI trusts messages from grok-ai.easytool.dev, so content from that origin can ask it to extract the page URL, title, and DOM text.
The bridge can also get or set chrome.storage.local values without a consent prompt.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-940
- Source
- Dynamic sandbox
The user installs the extension.
The extension trusts messages from grok-ai.easytool.dev and can process requests for page content or chrome.storage.local access.
- Current page URLhttps://example.com/article (illustrative)
Shows which page the user is viewing when the request runs.
- Page titleExample Article Title (illustrative)
Provides readable context about the active page.
- DOM contentVisible article text from the page (illustrative)
Can include visible text from the active page, including page-specific details.
- Extension storage datasavedPreference=true (illustrative)
Can include values saved by the extension in chrome.storage.local.
Dynamic analysis confirmed that the trusted-origin message handler routes page-content and storage requests to page extraction and chrome.storage.local handlers.
What it can do
Permissions this extension asks for, as declared in version 3.1.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Store data in your browser
storage
Show a panel beside the page
sidePanel