Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeHARPA AI: Web Automation with ChatGPT, Claude, Gemini, Grok
Findings · 3
+8 more findings locked
CRITICAL FINDINGS · 3
  1. 01AI-generated JavaScript from remote LLM response is compiled with `new Function()` and executed in user's active tab page-context, with a `<div onreset>` dispatchEvent CSP-bypass fallback when pages set strict CSP
  2. 02Browsing history transmitted to harpa.ai servers via compressed request headers
  3. 03Full contents of the user's Google Sheets are silently fetched via `docs.google.com/spreadsheets/d/<id>/export?format=csv` (same-origin cookies) and forwarded to the AI chat backend as page context, including data in hidden rows/columns beyond what the user currently sees on screen
+8 more findings locked
OTHER EXTENSIONS

Is HARPA AI: Web Automation with ChatGPT, Claude, Gemini, Grok safe?

Critical risk

No summary available.

HARPA AI LLCv13.1.0Chrome Web Store
100Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+8 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026eanggfilgoajaocelnaflolkadkeghjp

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact