Prettify Hku Chatgpt Chrome extension icon

Prettify Hku Chatgpt

✨ AI-Powered 🔍 Security Report Available
👥 2 users
📦 v1.0
💾 20.62KiB
📅 2025-06-11
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Overview

Make HKU ChatGPT usable again!

Tags

Productivity/tools productivity/tools

Privacy Practices

Not being sold to third parties, outside of the approved use cases
Not being used or transferred for purposes that are unrelated to the item's core functionality
Not being used or transferred to determine creditworthiness or for lending purposes
v1.0 Info Scanned Mar 11, 2026

Security Analysis — Prettify Hku Chatgpt

Analyzed v1.0 · Mar 11, 2026 · 1 JS files · 9 KB scanned

Permissions

https://chatgpt.hku.hk/*

Code Patterns Detected

innerHTML assignment — potential XSS vector

Package Contents 9 files · 27KB

📁_metadata2KB
{}verified_contents.json2KB
📁icons12KB
🖼icon128.png9KB
🖼icon16.png375B
🖼icon32.png948B
🖼icon48.png2KB
📄README.md519B
📜content.js9KB
{}manifest.json640B
🎨style.css3KB

What This Extension Does

Prettify HKU ChatGPT is a productivity tool designed to improve the visual layout and usability of the official HKU ChatGPT interface. It operates by injecting content scripts into specific pages to modify HTML elements, aiming to fix rendering issues or enhance readability for users. With minimal network activity and standard permissions, it presents a low-risk profile typical of utility extensions.

Permissions Explained

  • https://chatgpt.hku.hk/*expected: This permission allows the extension to run code only on the specific HKU ChatGPT website. It ensures the tool cannot see or modify data on other websites you visit, keeping your browsing activity elsewhere private.
    Technical: Manifest V3 'host_permissions' scope restricting content script injection and API access to a single origin. Limits attack surface by preventing cross-site context manipulation. No broad network sniffing capability granted.

Your Data

The extension does not send any data to external servers. It operates entirely locally within your browser session on the HKU ChatGPT domain, meaning no personal information leaves your device.

Technical Details

Network monitoring indicates zero outbound connections from the extension context. No cookies, tokens, or page content are transmitted to third-party domains. All processing occurs in-memory via Content Scripts injected into https://chatgpt.hku.hk/*.

Code Findings

Potential XSS Vector via innerHTML AssignmentMedium

The extension modifies the webpage by directly inserting user-generated or fetched text into HTML elements. If the extension ever pulls content from an untrusted source and inserts it without cleaning, a hacker could theoretically inject malicious code that runs in your browser.

Technical: Code pattern: element.innerHTML = ... detected in the single JavaScript file (9 KB). This DOM manipulation method is susceptible to Cross-Site Scripting (XSS) if the string being assigned contains script tags or event handlers. Risk is elevated only if the extension fetches external data; currently, it appears to target static page elements.

💡 Content scripts frequently use innerHTML to replace broken layouts, add buttons, or fix CSS rendering issues on third-party sites where standard CSS injection fails.

Missing Content Security Policy (CSP)Low

The extension does not enforce strict security rules to prevent scripts from running. While this is common for small tools, it means the browser relies solely on its default protections rather than an additional layer of defense against code injection.

Technical: Audit shows Content-Security-Policy header or meta tag is not set within the extension's context. Without a custom CSP, the extension cannot restrict which scripts are allowed to execute in its own context, potentially allowing unintended script execution if combined with other vulnerabilities.

💡 Many lightweight extensions omit CSP headers to avoid breaking functionality on complex sites that rely on specific script loading behaviors.

Bottom Line

Prettify HKU ChatGPT is a safe utility for fixing display issues on the HKU platform, provided users do not enable any 'fetch' or external data features. The primary technical risk is a standard DOM manipulation vulnerability (innerHTML) that exists in many layout-fixing tools but is currently low-risk given the extension's limited scope and lack of network access. Users should keep the extension updated to ensure this code pattern remains secure.

Similar Extensions

More in Productivity/tools →
Easy-to-use PDF tools to view, edit, convert, fill, e-sign PDF files, and more in your browser.
Productivity/tools AI

Zotero Connector

7M+ users
Save references to Zotero from your web browser
Productivity/tools
Browsec VPN is a Chrome VPN extension that protects your IP from Internet threats and lets you browse privately for free…
Productivity/tools