Check your browsers and accounts
Browser extensions are where the surprise usually is. Incogni analysed 442 AI-powered Chrome extensions in January 2026 and found 52% collected at least one type of data, and 42% held the scripting permission that lets an extension change the pages you load.
Short on time? Do steps 1, 2 and 4 or 5, then jump to the prompt. The rest can wait.
- Open a blank note and call it "What can reach my stuff". For each thing, write its name, where it lives and what you think it does, even if that is "no idea". Names only, never a password or key. This note goes into the prompt, and writing first stops you deleting something you rely on in a panic.
- List your Chrome extensions. Click the three-dot More menu, then Extensions, then Manage extensions (Google's help page). Write down every one, including those without "AI" in the name, because AI helpers often hide behind brand names. Each one's Details page shows its site access, where you can later limit it. On a work computer, leave anything your employer installed alone.
- Do the same in every other browser you use. In Safari on a Mac, go to Safari, then Settings, then Extensions (Apple's guide). In Edge, open Settings and more, then Extensions, then Manage extensions (Microsoft's guide). In Firefox or Brave, find Extensions or Add-ons in the main menu. Each browser keeps its own list, so check every one you use.
- Check what Claude is connected to. In Claude, open Settings (or Customize), find Connectors and note each one, such as Gmail or Google Drive (Anthropic's help page shows how to disconnect). A connector lets Claude reach into that account while you chat, and it lives in your Claude account on the web, so nothing on your computer can see it.
- Check what ChatGPT is connected to. In ChatGPT's settings, find the apps or connectors you have linked and write each one down (OpenAI's help page on connectors). The same reason applies: the link lives in your ChatGPT account, out of reach of anything on your computer.
- Check which apps can reach your Google account. Go to myaccount.google.com/linkedapps, which lists the apps you have given access to your Google account (Google's help page). Note the AI ones and any you do not recognise, because this is where an AI app you tried once and forgot keeps its access to your Gmail, Drive or calendar.
If something on the list is plainly junk, remove it now. For everything else, take the note to the prompt further down.
If you use Claude Code or a desktop AI app
Desktop AI apps keep their own connections, and those never show up in a browser. In Claude Code, three commands cover it:
claude mcp listshows every connected MCP server, a small add-on that lets the AI reach another tool, like your files or a database./mcpopens the panel where you can switch one off or clear its sign-in./permissionsshows what you have already approved.
Add each one to your note the same way, and treat anything you do not recognise as unrecognised. On a work computer, leave anything your employer set up alone.
Where the line is
- This is an inventory, and an inventory cannot tell you that you are safe. It tells you what can reach your accounts and files, and nothing about whether any of it has misbehaved. The prompt says the same thing if you ask it.
- It misses what is tucked away. An AI tool inside a desktop app you have not opened for months, or a script in a folder you forgot, will not appear on any browser or account page, so if you have ever installed a desktop AI app, check inside it as well.
How to judge each thing on your list
Simon Willison's post The lethal trifecta for AI agents names the three ingredients that, together, let someone steal your data through an AI tool:
- Access to your private data. Your email, files, calendar or accounts.
- Exposure to untrusted content. Anything written by someone else, like a web page or an email from a stranger.
- The ability to send things out. Post, email, upload or delete.
Plenty of useful tools have one or two. A tool with all three can be tricked by text hidden in an email or a web page into sending your data somewhere, so those are the ones to limit or remove first. A Gmail connection already has the first two, so what decides it is whether it can also send.
The Keep, Limit or Remove Check
Paste this into Claude or ChatGPT, fill in the two parts in brackets, and put your note in the last one. It starts from what it already knows about how you use it, checks that with you, and asks what you rely on before it judges anything, then goes item by item and tells you exactly where to click.
You are my calm, careful tech-savvy friend, the one who knows how browser extensions, AI connectors and desktop AI tools work, and the reason I finish this knowing exactly what can reach my email, my files and my passwords. You explain everything in plain words, and you never scare me or guess. Your job is to go through the list I give you, one item at a time, and help me decide what to keep, what to limit and what to remove. This is a tidy-up of what can reach my computer and accounts. If I ask whether I am "safe" now, say plainly that this check cannot tell me that. START FROM WHAT YOU ALREADY KNOW ABOUT ME You have seen how I use you: what I ask for, how often, which files and accounts come up, and how technical I am. Use that as your picture of my setup and my habits before you judge anything, and open by saying in two lines what you are assuming about me, so I can correct it. If you have no memory of our past chats, ask me two questions before going on: what I use AI for each week, and whether this computer and the accounts on my list are mine, work ones or shared. WHAT WORRIES ME MOST [The one or two things that made you want to do this, in your own words, so it deals with those first. For example: "I connected Gmail to ChatGPT months ago and have no idea what it can do with it. And there is a Chrome extension called Tab Helper that I do not remember installing."] WHAT I FOUND [Paste your list, one item per line: its name, where it lives (Chrome, Safari, Edge, Claude connectors, ChatGPT, Google account, or a desktop AI app) and what you think it is for, even if the answer is "no idea". Names and labels only: never paste the value of a password, API key or token, even if you can see it. For example: "Tab Helper, Chrome extension, no idea what it is." "Gmail, connected to ChatGPT, I think for summarising emails."] HOW TO WORK THROUGH IT Go in these stages, in order, and do not skip ahead to verdicts. STAGE 1, ASK FIRST AND WAIT. Read the whole list. If WHAT I FOUND is empty, ask me to paste my list and stop there. Otherwise ask me one numbered list of short questions, with quick answers to pick from: - for every item where you cannot tell whether I still use it: "use it weekly", "tried it once", "no idea what this is"; - for every connector or linked app that reaches my email, files or calendar: "When you connected it, did it ask to send, post or delete as well as read?" with "yes", "only read", "not sure". Skip anything I have already explained. If more than ten items need a question, group them by where they live and ask one question per group. Then stop and wait for my answers before you judge anything. STAGE 2, SAY WHAT EACH ONE IS. For each item, write one plain line on what it is, but only if you recognise it with confidence from its name and the details I gave. If you do not recognise it, write exactly "I do not recognise this, look it up before deciding" and move on. Never guess what an unknown item does from its name, and never assume two items with similar names are the same thing. If the exact same app name appears in two places, such as a Gmail connector in Claude and Claude in my Google linked apps, treat it as one item and tell me both places it can be switched off. If the names only look alike, ask me. STAGE 3, WEIGH IT AGAINST THE THREE RISKS. Simon Willison names three ingredients that together let someone steal data through an AI tool: access to my private data, exposure to untrusted content (anything someone else wrote, like a web page or an email from a stranger), and the ability to send things out. For each item, say which of the three it has, based only on what I told you, and write "not clear from the list" where you cannot tell. Then apply these rules: - If an item has all three, put it at the top and explain in one sentence why that combination is the risk. - If an item can read and change every website I visit, count it as private data plus untrusted content, because that includes the sites I am logged into. - If an item can run programs on my computer, tell me that in plain words. - If an item is a hook, tell me it runs by itself each time its trigger happens, without asking me. - If an item is a password or key sitting in a settings file, name the key and the file, tell me to rotate it (make a new key in the service that issued it and delete the old one), and never ask me for the value. - If I told you it can send, post or delete, count it as able to send things out. - If an item can read files well beyond one folder, count it as private data. - If the origin is UNKNOWN-ORIGIN, or a git repo, local script or remote server I did not say I added, treat it as unrecognised. - If I use something every week and it has wide access, lean LIMIT, such as setting a browser extension's site access to only the sites it needs. - If I use it every week and it has all three, lean LIMIT and name which of the three to cut. If you know of no setting that cuts one, say so and let me choose between keeping and removing it. Never make up a setting. - If I say an item is on a work computer or a work account, or that my organisation installed it, send me to my IT team instead of telling me to remove it. - If I tried it once or said I do not remember it, lean REMOVE, and tell me I can add it back later if I miss it. - Then look across the items that live in the same AI app (all my Claude connectors together, all my ChatGPT connectors together). If between them they cover all three, say so, because the AI can use them together in one chat, and name the one to cut. STAGE 4, GIVE ME THE VERDICTS. One line per item, in this order: REMOVE first, then ROTATE, then LOOK IT UP FIRST, then LIMIT, then KEEP. Each line starts with the verdict, then: the name | what it is, or "I do not recognise this, look it up before deciding" | which of the three risks it has | one reason | exactly where to go to do it. Use ROTATE for any key or token I told you is sitting in a settings file. Use LOOK IT UP FIRST for anything you could not identify, and add that if I still cannot tell what it is after looking, removing it is the safer choice. For where to go, use only these places: - Chrome: the three-dot More menu, then Extensions, then Manage extensions. Remove it there, or open Details to limit its site access. - Safari on a Mac: Safari, then Settings, then Extensions. Untick it to turn it off, or select it and click Uninstall. - Edge: Settings and more, then Extensions, then Manage extensions, then Remove from Microsoft Edge. - Claude: in Claude, open Settings (or Customize) and find Connectors, then disconnect it. - ChatGPT: in ChatGPT's settings, find the apps or connectors I have linked and disconnect it. - Google account: myaccount.google.com/linkedapps, pick the app, See details, Remove access, then Confirm. - Anything that lives inside a desktop AI app (Claude Code, Claude Desktop, Cursor, VS Code and the like): tell me to remove it from inside that app's own settings or to ask someone technical I trust. Never give me commands to type or files to delete. If an item lives somewhere not on this list, write "I am not sure of the exact menu, search that app's help for how to remove it". Never make up a menu path. STAGE 5, CHECK YOUR WORK. Before you finish, count the items on my list and the verdicts you gave, and confirm the two numbers match (an app you treated as one item counts once). List every item you could not identify. Name the one verdict you are least sure about and why. Confirm you invented no menu path, no company, no feature and no fact about any item. Confirm you never asked for or repeated a secret value. Then tell me the two things to do first, and ask if I want the first one walked through click by click. WHEN I COME BACK - If I say "I want to add a new one" and name it, run Stages 2 and 3 on that one item before I install it: which of the three risks it adds, whether it completes all three alongside anything I kept, and the narrowest setting to choose if you know one. If you do not recognise it, say so. - If I say "check again" and paste a fresh list, compare it with your last verdicts: confirm what is gone, flag anything new, and flag anything marked REMOVE that is still there. RULES - Plain words, [your spelling preference], short sentences. Explain any technical word the first time you use it. - Never ask me for a password, key or token. If I paste one by mistake, tell me to rotate it, and do not repeat it back. - If I sound panicked, give me the two things to do first before the full list.
The check, filled in
So the brackets are not a mystery, here is the check filled in for an illustrative creator whose ChatGPT and Claude already remember how she works, followed by a shortened version of the answer it gives back. The list and the names in it are made up for the example. Yours will be your own.
WHAT WORRIES ME MOST I connected Gmail to ChatGPT months ago and do not know what it can do. And there is a Chrome extension called Tab Helper I do not remember installing. WHAT I FOUND Tab Helper, Chrome extension, no idea what it is Grammar checker, Chrome extension, I use it every day Google Drive, Claude connector, for my newsletter notes Gmail, ChatGPT connector, I think for summarising emails Meeting note-taker, has access to my Google account, tried it once in May WHAT CAME BACK (shortened) It opened with what it assumed: a MacBook, Chrome daily, ChatGPT for captions most days and Claude for a Friday newsletter from Drive notes, not technical, personal accounts. Then it asked three questions and waited: "1. The Gmail connector: do you use it now? use it weekly / tried it once / no idea. 2. When you connected Gmail, did it ask to send or delete email as well as read it? yes / only read / not sure. 3. When you connected Google Drive to Claude, did it ask to edit or delete files as well as read? yes / only read / not sure." The answers were "tried it once", "not sure" and "only read". REMOVE | Gmail, ChatGPT connector | lets ChatGPT reach your Gmail | private data and untrusted content (emails from strangers); sending is not clear, since you were not sure | you tried it once, it has two of the three, and it may have the third | ChatGPT settings, apps or connectors, disconnect REMOVE | Meeting note-taker | an app with access to your Google account | private data; the rest is not clear from the list | tried once in May | myaccount.google.com/linkedapps, pick it, See details, Remove access, Confirm LOOK IT UP FIRST | Tab Helper | I do not recognise this, look it up before deciding | not clear from the list | you do not remember installing it; if you still cannot tell after looking, remove it | Chrome, More, Extensions, Manage extensions LIMIT | Grammar checker | a writing extension you use daily | site access not clear from the list | you rely on it, so narrow it to the sites you write on | Chrome, More, Extensions, Manage extensions, Details, site access KEEP | Google Drive, Claude connector | lets Claude read your Drive files | private data; it only reads, from what you said | you use it every Friday | Claude Settings (or Customize), Connectors, if you ever stop Check: 5 items, 5 verdicts. Could not identify: Tab Helper. Same-app check: nothing in Claude or in ChatGPT adds up to all three from what the list says. Least sure about: the Gmail connector, because you were not sure whether it can send, which would give it all three. No menu paths or facts invented, and no secret value asked for or repeated. Do first: disconnect Gmail from ChatGPT, then remove the meeting note-taker's Google access. Want the first one walked through click by click?
Notice what it did with Tab Helper. It had no idea what it was, so it said so and sent you to look, which is the behaviour you want from anything judging what is on your computer.
To look something up, open its Details page in Manage extensions and search its exact name along with the word "extension". Three things point to removing it:
- You do not remember adding it.
- It has site access set to "On all sites".
- You cannot find a proper store page for it.
Some desktop programs add a browser extension while they install, which is often how a Tab Helper gets there without you choosing it.
Check it worked
Once you have acted on the verdicts, go back to the same pages and check:
- The removed extensions are gone from Manage extensions.
- The disconnected apps are gone from Connectors and from your Google linked apps page. If Claude or ChatGPT still appears there after you disconnect it, remove its access there too.
- Any key you rotated: the old one stops working for whatever used it, which is fine if you removed that tool as well, and a tool you kept will need the new key.
Do it now
Start with the browser you use most and the connectors in whichever chat app you use, paste that short list into the check, and act on the first thing it tells you to do. The rest can wait until tomorrow, and repeating the check every few months keeps the list short enough to stay on top of.
One quick question
Should I paste my API keys into Claude or ChatGPT so it can check them?
No. Paste the key's name and where it lives, never the value. If a key is sitting in a settings file, the fix is to rotate it: make a new key in the service that issued it and delete the old one.