Is "BURKA Privacy Shield" on Chrome Web Store Safe to Install?
AI Privacy Shield – Protect Your Sensitive Data in AI Chats AI Privacy Shield helps keep your personal and sensitive information safe while using AI platforms like ChatGPT. It automatically detects and masks sensitive data before your message is sent, and restores it locally after the response is generated. Everything happens on your device. No servers involved. ⸻ Why use AI Privacy Shield When using AI tools, you may unintentionally share information such as: • Email addresses and phone numbers • Salary or financial details • Passwords, OTPs, tokens • Crypto wallet addresses This extension ensures that such data is never sent in its original form. ⸻ How it works 1. You type your prompt normally 2. The extension detects sensitive information 3. It replaces the data with placeholders like [CONFIDENTIAL_1] 4. The masked prompt is sent to the AI 5. Original values are restored in your browser view ⸻ Key features • Local-first processing with no backend servers • Pattern-based detection of common sensitive data • Encrypted storage of placeholder mappings using Web Crypto (AES-GCM) • Automatic restoration of masked values in responses • Simple controls with global and platform-specific toggles ⸻ Supported platforms • ChatGPT (chatgpt.com, chat.openai.com) Support for more platforms is planned. ⸻ Privacy • No data collection • No tracking • No external API calls All processing and storage remain on your device. ⸻ Notes • Works on text inputs only • Dynamic website updates may require a refresh • Detection is pattern-based and may occasionally mask extra content ⸻ Who it is for • Students using AI tools • Developers handling credentials or tokens • Professionals working with sensitive information • Anyone who wants more control over their privacy ⸻ Install AI Privacy Shield to reduce the risk of exposing sensitive information while using AI tools.
Risk Assessment
Analyzed76 security findings detected across all analyzers
Chrome extension requesting 18 permissions
Severity Breakdown
Finding Categories
YARA Rules Matched
7 rules(21 hits)Requested Permissions
18 permissionsAbout This Extension
Detailed Findings
23 totalYARA Rule Matches
7 rulesIndicators of Compromise
Network indicators, suspicious strings, and potential IoCs extracted during analysis
All Indicators · 53
detected URL: https://clients2.google.com/service/update2/crx XIOC detected URL: https://clients2.google.com/service/update2/crx
extracted_from_files
detected Domain: event.target XIOC detected Domain: event.target
extracted_from_files
detected IP: ::bef XIOC detected IP: ::bef
extracted_from_files
detected URL: https://*.meta.ai/* XIOC detected URL: https://*.meta.ai/*
extracted_from_files
detected URL: https://llama.com/* XIOC detected URL: https://llama.com/*
extracted_from_files
detected URL: https://*.llama.com/* XIOC detected URL: https://*.llama.com/*
extracted_from_files
detected URL: https://gemini.google.com/* XIOC detected URL: https://gemini.google.com/*
extracted_from_files
detected URL: https://*.gemini.google.com/* XIOC detected URL: https://*.gemini.google.com/*
extracted_from_files
detected URL: https://grok.com/* XIOC detected URL: https://grok.com/*
extracted_from_files
detected URL: https://*.grok.com/* XIOC detected URL: https://*.grok.com/*
extracted_from_files
detected URL: https://x.com/* XIOC detected URL: https://x.com/*
extracted_from_files
detected URL: https://*.x.com/* XIOC detected URL: https://*.x.com/*
extracted_from_files
detected URL: https://meta.ai/* XIOC detected URL: https://meta.ai/*
extracted_from_files
detected Domain: 3v.uy XIOC detected Domain: 3v.uy
extracted_from_files
detected Domain: v.bo XIOC detected Domain: v.bo
extracted_from_files
detected URL: https://*.chatgpt.com/* XIOC detected URL: https://*.chatgpt.com/*
extracted_from_files
detected URL: https://chat.openai.com/* XIOC detected URL: https://chat.openai.com/*
extracted_from_files
detected URL: https://*.chat.openai.com/* XIOC detected URL: https://*.chat.openai.com/*
extracted_from_files
detected URL: https://claude.ai/* XIOC detected URL: https://claude.ai/*
extracted_from_files
detected URL: https://*.claude.ai/* XIOC detected URL: https://*.claude.ai/*
extracted_from_files
detected Domain: msg.content.map XIOC detected Domain: msg.content.map
extracted_from_files
detected Domain: parsed.contents.map XIOC detected Domain: parsed.contents.map
extracted_from_files
detected Domain: item.parts XIOC detected Domain: item.parts
extracted_from_files
detected Domain: item.parts.map XIOC detected Domain: item.parts.map
extracted_from_files
detected Domain: xmlhttprequest.prototype.open XIOC detected Domain: xmlhttprequest.prototype.open
extracted_from_files
detected Domain: origopen.call XIOC detected Domain: origopen.call
extracted_from_files
detected Domain: origsend.call XIOC detected Domain: origsend.call
extracted_from_files
detected Domain: nodefilter.show XIOC detected Domain: nodefilter.show
extracted_from_files
detected Domain: mut.target XIOC detected Domain: mut.target
extracted_from_files
detected Domain: query.content.parts XIOC detected Domain: query.content.parts
extracted_from_files
detected Domain: content.parts XIOC detected Domain: content.parts
extracted_from_files
detected Domain: parts.map XIOC detected Domain: parts.map
extracted_from_files
detected Domain: parsed.messages.map XIOC detected Domain: parsed.messages.map
extracted_from_files
detected Domain: msg.content.parts XIOC detected Domain: msg.content.parts
extracted_from_files
detected Domain: window.top XIOC detected Domain: window.top
extracted_from_files
detected Domain: chrome.storage XIOC detected Domain: chrome.storage
extracted_from_files
detected Domain: e.detail.map XIOC detected Domain: e.detail.map
extracted_from_files
detected Domain: event.data XIOC detected Domain: event.data
extracted_from_files
detected Domain: data.map XIOC detected Domain: data.map
extracted_from_files
detected Domain: valuesetter.call XIOC detected Domain: valuesetter.call
extracted_from_files
detected URL: https://chatgpt.com/* XIOC detected URL: https://chatgpt.com/*
extracted_from_files
detected Domain: i.ir XIOC detected Domain: i.ir
extracted_from_files
detected Domain: gemini.google.com XIOC detected Domain: gemini.google.com
extracted_from_files
detected Domain: meta.ai XIOC detected Domain: meta.ai
extracted_from_files
detected Domain: llama.com XIOC detected Domain: llama.com
extracted_from_files
detected Domain: status-pill.off XIOC detected Domain: status-pill.off
extracted_from_files
detected Domain: platforms.map XIOC detected Domain: platforms.map
extracted_from_files
detected Domain: tab.id XIOC detected Domain: tab.id
extracted_from_files
detected Domain: chat.openai.com XIOC detected Domain: chat.openai.com
extracted_from_files
detected Domain: copilot-instructions.md XIOC detected Domain: copilot-instructions.md
extracted_from_files
detected Domain: policy.md XIOC detected Domain: policy.md
extracted_from_files
detected Domain: r.se XIOC detected Domain: r.se
extracted_from_files
detected Domain: 䘧.km XIOC detected Domain: 䘧.km
extracted_from_files
AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-27. The review verdict is likely false positive with 82% confidence.
Recommended action: suppress false positive.
Risk context: MEDIUM risk, score 62/100.
Evidence context: threat category none; evidence quality moderate.
The BURKA Privacy Shield extension demonstrates clear false positive patterns in its CVEQ findings. The extension's stated purpose is to "mask sensitive data before sending to AI platforms," which directly explains the presence of legitimate AI platform URLs in the IoC findings.
The IoC findings reveal a pattern of extraction errors rather than malicious behavior. The finding XIOC-DOMAIN-msg.content.map is not a domain—it is JavaScript property access (msg.content.map) being misread by the XIOC extractor as a domain. Similarly, XIOC-DOMAIN-parsed.contents.map, XIOC-DOMAIN-item.parts, and XIOC-DOMAIN-item.parts.map are all JavaScript method chains from the extension's content masking logic, not network destinations. The finding XIOC-DOMAIN-xmlhttprequest.prototype.open is a JavaScript API reference, not a domain. These are documented false positive patterns in the CVEQ IoC extractor.
The legitimate URLs detected—https://chat.openai.com/*, https://*.claude.ai/*, meta.ai, and https://*.x.com/*—are consistent with the extension's stated functionality. A privacy extension that masks data before AI platform interactions must interact with these platforms. These are not suspicious domains; they are the exact platforms the extension is designed to protect users on.
The findings summary shows zero malware signatures, zero obfuscation findings, and only 2 network findings. The 21 code-smell findings are classified as low severity and represent generic JavaScript patterns (per the CVEQ false positive documentation, these are noise and should not drive verdicts). The absence of malware signatures and obfuscation is a strong indicator of benign intent.
The strongest counterargument would be that the extension accesses AI platform URLs and could exfiltrate user data. However, this ignores the extension's explicit purpose: it masks sensitive data before sending to AI platforms. Accessing these platforms is necessary for its function. There is no evidence of data exfiltration to unknown or suspicious domains—all detected URLs are legitimate AI and social media platforms. The developer uses a Gmail address ([email protected]), which is common for privacy-focused independent developers, and the low user count (8) is typical for niche privacy tools rather than an indicator of malicious intent.
This extension should be classified as a false positive from the automated detection system.
Key Reasons
- IoC findings are JavaScript property access chains misread as domains (msg.content.map, item.parts, xmlhttprequest.prototype.open)
- Legitimate AI platform URLs (chat.openai.com, claude.ai, meta.ai) match extension's stated privacy masking purpose
- Zero malware signatures and zero obfuscation findings
- Code-smell findings are low-severity noise per CVEQ documentation
False Positive Considerations
- JavaScript property access chains misread as domains by XIOC extractor
- Legitimate platform URLs matching extension functionality
- Code-smell findings classified as low severity noise
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng
[email protected]
SVG to AVIF Converter [ShiftShift]
[email protected]
ChromeCompare
[email protected]
CAI Tools
[email protected]
Auto Gmail - ChatGPT AI for email inbox
[email protected]
EC Seller Tools
[email protected]