Chrome Web Store Verified

Superhuman Go: AI Assistant

by [email protected] · 20.0K users · 3.8 rating
47f3e2d3-881d-5b42-9ff8-4710a3c45c0e | v1.21.0
65/ 100
MEDIUM risk
No change since v1.19.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
4 days ago
Version
v1.21.0
Artifact
SHA256 6C9…1EB
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows

YARA Rule Matches

18 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 55
src/js/8954.libs.chunk.jssrc/js/5457.vendors.chunk.jssrc/js/3327.vendors.chunk.js +52 more
-
LOWcredential env files 31
src/js/79.libs.chunk.jssrc/js/8954.libs.chunk.jssrc/js/SduiInlineEngineIntegration.common.chunk.js +28 more
-
LOWpostinstall file download 94
src/js/8137.libs.chunk.jssrc/js/7219.vendors.chunk.jssrc/js/4873.libs.chunk.js +91 more
-
LOWNoUseWeakRandom 73
src/js/9970.vendors.chunk.jssrc/js/Grammarly-check.jssrc/js/g2.common.chunk.js +70 more
-
LOWNoUseEval 2
src/js/2515.vendors.chunk.jssrc/js/humanWritingReport.common.chunk.js
-
LOWUntrustedContentShouldNotBeIncluded 1
src/js/Grammarly-gDocsEarlyInjector.js
-
LOWSQLInjection 13
src/js/g2.common.chunk.jssrc/js/3178.libs.chunk.jssrc/js/4905.vendors.chunk.js +10 more
-
LOWLocalStorageShouldNotBeUsed 16
src/js/9456.libs.chunk.jssrc/js/7861.libs.chunk.jssrc/js/Grammarly-gDocs.js +13 more
-
LOWcredential metamask extension 1
src/js/Grammarly.js
-
LOWDebuggerStatementsShouldNotBeUsed 11
src/js/Grammarly.jssrc/js/2515.vendors.chunk.jssrc/js/Grammarly-gDocs.js +8 more
-
LOWUsingCommandLineArguments 1
src/js/Grammarly-bg.js
-
LOWpostinstall crypto operations 67
src/js/6273.common.chunk.jssrc/js/1212.vendors.chunk.jssrc/js/8961.libs.chunk.js +64 more
-
LOWpostinstall file manipulation 287
src/js/6283.libs.chunk.jssrc/js/2023.common.chunk.jssrc/js/8961.libs.chunk.js +284 more
-
LOWpostinstall environment access 3
src/js/Grammarly.styles.jssrc/inkwell/assets/index-uVYElzgq.jssrc/js/Grammarly-gDocs.styles.js
-
LOWpostinstall registry modification 30
src/js/2791.vendors.chunk.jssrc/js/Grammarly-sidePanel.jssrc/js/2515.vendors.chunk.js +27 more
-
LOWAlertStatementsShouldNotBeUsed 1
src/js/Grammarly-check.js
-
LOWpostinstall obfuscation 134
src/js/9421.vendors.chunk.jssrc/inkwell/assets/index-BM-moq3b.jssrc/js/Agents-StaticSelectionIntegration.common.chunk.js +131 more
-
LOWpostinstall system command 159
src/inkwell/assets/index-LtbzZSV1.jssrc/js/2515.vendors.chunk.jssrc/inkwell/assets/index-BM-moq3b.js +156 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

3,557 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

57
Noisy-finding weight
x1.00
Publisher domain
grammarly.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

14
Obfuscation
5
Network
3,557
IoC Indicators

YARA Rules Matched

18 rules(979 hits)
postinstall persistence mechanism credential env files postinstall file download NoUseWeakRandom NoUseEval UntrustedContentShouldNotBeIncluded SQLInjection LocalStorageShouldNotBeUsed credential metamask extension DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments postinstall crypto operations postinstall file manipulation postinstall environment access postinstall registry modification AlertStatementsShouldNotBeUsed +2 more

Requested Permissions

11 permissions
nativeMessaging

Exchange messages with programs outside the browser

Dangerous
http://*/*
Dangerous
https://*/*
Dangerous
cookies

Read and modify cookies on all sites

High
identity

Access your identity and sign-in tokens

High
clipboardRead

Read data from your clipboard

High
tabs
Medium
scripting
Low
sidePanel
Low
notifications
Low
storage
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Superhuman Go is published by Grammarly ([email protected]), the widely-used writing assistant with millions of active users. The extension declares no host permissions and requests no special API access, which aligns with a tool that inspects and augments text within standard web forms.

The findings bundle reports 4912 total findings, but this count is driven almost entirely by two known false-positive sources. First, the obfuscation detections (UNICODE_HEAVY and LARGE_BASE64) all appear in vendor chunk files (2515.vendors.chunk.js, 7422.vendors.chunk.js, Grammarly-check.js, etc.). These file paths and naming patterns are characteristic of webpack or esbuild bundled output, where minified third-party libraries are normal. Minification and bundled dependency code routinely trigger unicode and base64 obfuscation rules without indicating malicious intent.

Second, the IoC extractor produced 3559 findings, but none of the network endpoints in the bundle are specific, suspicious domains. The listed endpoints (1w.gy, 3-o.md, 3e3-date.now, 54-i.client.top, account.ppgr.io, adnxs.com, adsrvr.org) are either fragmented property chains from minified code misread as domains, or they are generic advertising/analytics infrastructure. The presence of adnxs.com and adsrvr.org (both legitimate ad networks) in a list of thousands is expected noise from bundled vendor code and does not indicate active malicious behavior. No malware signatures matched the scanned files, and the extension's declared behavior (grammar checking and AI assistance) does not require the hostile capabilities (credential theft, hijacking, proxyware) that would justify the obfuscation findings if they were real.

A skeptic might note that obfuscation findings exist at all, or that the extension does make network calls (NET-WEBSOCKET, NET-FETCH). However, grammar checking inherently requires network communication to reach Grammarly's backend services. The specific network findings are generic API usage patterns found in distributed JavaScript chunks, not indicators of hidden payloads. A legitimate writing-assistant extension must talk to its backend; the obfuscation findings in production bundles are noise, not evidence of concealment. The zero malware signatures, combined with Grammarly's known publisher status and the absence of any suspicious behavioral indicators, makes a malicious verdict unreasonable.

Key Reasons

  • Developer is Grammarly ([email protected]), a known, legitimate company with millions of users
  • Zero malware signatures matched despite 4912 total findings
  • Obfuscation findings are in vendor/libs chunk files, consistent with production bundled code
  • No host permissions or dangerous API access patterns
  • No typosquatting or impersonation indicators; extension name and description match legitimate product

False Positive Considerations

  • Bundled vendor/chunk JavaScript files trigger UNICODE_HEAVY and BASE64 obfuscation rules typical of webpack/esbuild output
  • Network findings (NET-WEBSOCKET, NET-FETCH, NET-JQUERY_AJAX) are generic API usage patterns in distributed chunks, not suspicious endpoints
  • 3559 IoC findings are from XIOC extractor noise (property chains, loopback IPs, CDN domains); zero malware signatures and no specific suspicious domains indicate false positives

Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 82%.

Chrome version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.0.3
May 29, 2026
Risk range
65 to 78
Across analyzed versions
Latest analyzed version
1.21.0
Sep 27, 2026
Selected version
medium
Version
v1.21.0
4 days ago
Risk score
65
Findings
4916
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Superhuman Go for Chrome is a proactive AI assistant that works alongside you across the web—understanding what you’re working on and stepping in with the right support at the right time. It brings AI directly into your workflow, so you can stay focused without switching tools or losing momentum. With the Superhuman Go extension, AI assistance is built into the way you work: • Works everywhere you work – Runs in every tab and web-based tool, ready when you are, without getting in the way. • Knows what you’re working on – Understands what’s on your screen, so you skip the copy-paste-and-explain step other AI tools require—no prompts or uploads needed. • Proactive, on your terms – Spots concrete ways to help—polishing a reply, prepping you for a meeting, summarizing a long thread—then surfaces them in the moment. Go suggests; you decide. • A team of specialized agents, managed for you – Go manages a growing team of specialized agents and brings in the right one at the right moment, so more capability never means more noise. • Connected to your tools – Safely integrates with 100+ apps like Gmail, Google Calendar, and Jira, so you can take action across your tools in the moment—with full control. • Backed by Grammarly – Built by the makers of Grammarly, with 16 years of writing expertise behind every suggestion. Add the Superhuman Go Chrome extension and sign up for Superhuman to start using Go for free. See how Superhuman Go handles your data: https://help.superhuman.com/hc/en-us/articles/47716615380109-Superhuman-Go-Data-Privacy-FAQ

Frequently Asked Questions