Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeZapier Agents
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01Window message listener in central-script.js accepts messages without origin validation, allowing any page framed or co-located on agents.zapier.com to trigger browser context and screenshot capture.
  2. 02Active tab content script reads full page text, title, and URL from every active tab and sends it to the agents.zapier.com iframe via the service worker message chain.
  3. 03Extension reads full Google Docs document content and Google Sheets data via authenticated API requests when user visits those pages.
+2 more findings locked
OTHER EXTENSIONS

Is Zapier Agents safe?

High risk

No summary available.

Zapierv1.4.30Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026jfcmjbboehfdmgbhheahjlnoimbgfdbn

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact