Dashboard

How to Vet an AI Browser Extension

The permission is read and change all your data on every site. Six checks before you install, and the one control almost nobody uses.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
13 September 20261 min read

How to Vet an AI Browser Extension

The permission that matters is the one worded as read and change all your data on all websites. An AI browser extension usually needs it to do anything useful, and granting it means the extension can see every page you open, including your webmail, your bank and your admin panels, and can alter them. The install-day question is whether you trust the developer. The real question, and the one people miss, is whether you will still be trusting them in a year, because extensions update silently and change hands quietly.

Why extensions are a different risk from web apps

A web app sees what you paste into it. An extension with broad host permissions sees everything, all the time, without you doing anything. That difference is structural, not a matter of degree:

Web app

Browser extension

Scope of access

What you send it

Every page you open

When it runs

When you visit it

Continuously, in the background

Session access

Its own

Any site you are logged into

Updates

Server side, visible in the product

Pushed to your browser automatically

The last row is the one that turns a fine extension into a bad one without any action from you. An extension you vetted in March is not the code running in your browser in October. Ownership changes are routine, and a new owner inherits the install base and the permissions along with it. This is a different risk from handing an agent a task on your behalf, which we cover in whether to let an AI agent use your browser.

The six-step check to vet an AI browser extension

  1. Read the permission list, not the description. In Chrome, the install dialogue and the extension's details page both show it. Broad host access plus the ability to read your browsing history is the combination worth pausing on.

  2. Find out who publishes it. A company with a real website, a named team and a privacy policy specific to the extension is a different proposition from a developer identified only by a Gmail address.

  3. Check the data disclosure the store requires. Look specifically for whether browsing data or personal communications are collected, and whether the publisher declares that data is sold to third parties. The declaration is self-reported, but a bad declaration is a definitive answer.

  4. Look at the update history and the review timeline. A long-dormant extension that suddenly updated, especially with a change of publisher name, is the classic pattern for a sold install base.

  5. Search for the extension name alongside terms such as acquired, sold, or malware. This takes thirty seconds and catches the well-documented cases.

  6. Decide where it is allowed to run. Both Chrome and Firefox let you restrict an extension to specific sites, or set it to run only when you click it. This is the single most effective control available and almost nobody uses it.

Step 6 deserves emphasis because it changes the risk profile more than any amount of research. An AI summarising extension does not need standing access to your bank. Setting it to on click means it reads a page only when you ask it to, which removes the continuous surveillance property entirely while keeping the feature.

What the AI part adds

Beyond normal extension risk, an AI extension has two properties worth separating:

  • Page content leaves your machine. To summarise or rewrite a page, the extension sends that page, or a large part of it, to a model provider. That includes any page with customer data, internal documents or a client's information on it.

  • It can act on the page. Extensions that fill forms, click, or navigate on your behalf are interpreting page content as instructions, which is a prompt injection surface: a malicious page can contain text aimed at the agent rather than at you.

The first has a compliance dimension people miss. If you handle client data under any confidentiality obligation, an extension that ships page content to a third party is a sub-processor you have not disclosed. Check the extension's own policy for whether content is retained or used for training, which is the same enquiry as checking whether an AI tool trains on your data. The second is the mechanism explained in what prompt injection is, and it applies with more force here because the attacker controls the page your extension is reading.

Signals worth refusing on

Signal

Why it matters

Broad host permissions with no explanation of why

A tool that cannot justify its access has not thought about it

No named publisher or a generic contact address

Nobody to hold responsible, and nothing to research

Store listing declares browsing data sold to third parties

That is the business model, and the feature is the collection mechanism

Large review count with a recent publisher change

Classic sold-install-base pattern

Free, with a heavy inference cost and no visible revenue model

Someone is paying for the tokens and it is worth knowing who

None of these are proof of anything on their own. Two together is enough to walk away, because there is almost always an alternative extension, and the cost of choosing the second-best one is trivial next to the cost of getting this wrong.

Reviewing what you already have

Most people accumulate extensions and never revisit them. Once a quarter, open your extensions page and do three things: remove anything you have not used in a month, switch everything remaining to on-click or site-restricted access where the feature still works, and check whether any publisher name has changed since you installed it.

For a team, this belongs in the same conversation as any other tool that touches company data. An extension installed on a work machine by one person has the same access as any approved vendor and went through none of the process, which is the definition of the problem in shadow AI. The general vendor questions in how to vet an AI vendor apply to extension publishers too, and are worth running for anything installed across more than a couple of machines. The wider picture sits in our overview of AI risks worth taking seriously.

Frequently asked questions

Are AI browser extensions safe to install?

Some are, and the risk depends far more on the publisher and the permissions than on the feature. An extension with read and change all your data access can see every page you open, so the practical question is whether you trust that publisher to still be trustworthy after the next silent update or change of ownership.

What does read and change all your data on all websites mean?

It means the extension can read the content of every page you visit and modify it, on any site, whether or not you are actively using the extension. That includes pages you are logged into, such as email, banking and internal tools.

Can I limit what a browser extension can see?

Yes, and you should. Both Chrome and Firefox let you restrict an extension to specific sites or set it to run only when clicked. For an AI extension that summarises or rewrites pages, on-click access preserves the feature while removing continuous access to everything else.

Does an AI extension send my page content to a server?

Almost always, because the model runs remotely. That means the content of any page you invoke it on, potentially including client or customer data, is transmitted to a third party. Check the publisher's policy for retention and training use before using it on anything confidential.

How do I tell if an extension has changed owners?

Compare the publisher name and website on the store listing with what you remember, and look at the update history for a long gap followed by sudden activity. A search for the extension name with the word acquired or sold usually surfaces the documented cases quickly.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.