DEV Community

Cover image for Is EasyGen Safe on LinkedIn? I Read Its Extension's Source Code as well
Michael Harris
Michael Harris

Posted on

Is EasyGen Safe on LinkedIn? I Read Its Extension's Source Code as well

Most of our reverse-engineering audits on LinkedIn tooling focus on heavy automation and outreach platforms — evaluating how tools like Linked Helper protect sessions via local desktop custody, or tracing how cloud and extension-based platforms (such as Waalaxy, HeyReach, Expandi, and Skylead) route session cookies and tokens through external servers.

Today, we are looking at an entirely different category: AI content creation and post-writing assistants. Specifically, EasyGen.

Note: This is not Woodward easYgen, Easygenerator LMS, or the EasyGen video app.

Verdict up front: Low risk, with five named residuals. EasyGen never reads or exports your LinkedIn session. It is a local post-writing extension, not outreach automation: zero leads, zero connections, zero messages.

Two prominent reviews reached the same low-risk verdict while claiming there was no Chrome extension at all. There is one. The vendor homepage does not prominently showcase it either, which explains the confusion. The useful correction is not a scarier verdict; it is an objective analysis based on the extension code that actually ships.

What EasyGen Actually Is

I audited Manifest V3 build v2.0.10 in the 2026-06-28 audit round. Its store snapshot showed 10,000 users and a listing last updated 2025-08-14. Research and corpus cross-checks were conducted in August 2026.

EasyGen is a local extension that mounts a React panel directly into LinkedIn's post composer. It reads and writes post copy in the active browser tab. It does not scrape profiles, invoke Voyager or GraphQL endpoints, extract or upload cookies, log into LinkedIn from remote cloud servers, schedule bulk actions, or operate a background queue.

Its extension ID, however, is present on LinkedIn's extension-probe catalog:

  • Active Extension Detection (AED): AED is not an industry buzzword or third-party label; it is the exact internal term found in LinkedIn's production JavaScript, where client-side scan results dispatch as an AedEvent. LinkedIn has never publicly acknowledged its existence.
  • The Probe Target: The specific check on 2026-06-28 probed tabs/auth-page.html, one of three declared web-accessible resources in the extension.

The Static Code Audit: Step by Step

These are static code signals rather than runtime telemetry. Each artifact below details its LinkedIn-facing detection consequence.

Step 1 — Inject the Panel

content.883ade9e.js [https://www.linkedin.com/](https://www.linkedin.com/)* all_frames: true Post / Login / OTP
Enter fullscreen mode Exit fullscreen mode

Detection consequence: Injection creates an inspectable surface for Spectroscopy (LinkedIn's recursive, list-free DOM scanner probing for chrome-extension:// resources) and server-side encrypted page snapshots. AED separately probes tabs/auth-page.html. all_frames: true ensures execution across embedded frames, not just the top-level document.

Step 2 — Read the Native Composer

.ql-editor[contenteditable='true'] .share-box .share-creation-state

Enter fullscreen mode Exit fullscreen mode

The content script initializes a MutationObserver to synchronize EasyGen's React UI with LinkedIn’s native editor (content.883ade9e.js:7150-7158).

Detection consequence: Zero independent network signals. Observing a contenteditable node produces no external network request.

Step 3 — Write Generated Text Back

editor.innerHTML = …
Enter fullscreen mode Exit fullscreen mode

Appears at content.883ade9e.js:7181 and :7279.

Detection consequence: None. Audited production code shows no active typing cadence or paste detection traps inside LinkedIn's composer.

Step 4 — Attach Media and Trigger Publication

new DragEvent("drop") 
dispatchEvent 
.share-box-footer__main-content 
.share-box-footer__primary-btn 
.click()
Enter fullscreen mode Exit fullscreen mode

Detection consequence: These synthetic DOM events carry isTrusted: false. Unlike human interaction, extensions cannot toggle this read-only browser flag. However, the surface remains narrow: one media drop and one programmatic click per user-initiated action—no recurring loops or timers.

Step 5 — Persist Drafts in Supabase

uubmmfnuqfibbobcoxej.supabase.co
.eq("supabaseUserId", …)
.eq("accountId", …)
@plasmohq/storage local
Enter fullscreen mode Exit fullscreen mode

The Supabase client authenticates with an anonymous key at content.883ade9e.js:14556.

Detection consequence: This is a data privacy vector, not a LinkedIn detection signal. Draft copy, generations, and EasyGen identifiers leave the browser for Supabase, but your LinkedIn credentials, session cookies, and profile metadata remain untouched.

Step 6 — Never Read the LinkedIn Session

permissions: ["storage"]
chrome.cookies      → 0 matches
li_at               → 0 matches
JSESSIONID          → 0 matches
li_a                → 0 matches
document.cookie     → 0 matches
Enter fullscreen mode Exit fullscreen mode

The bundle’s single cookies string belongs to internal Supabase Auth warnings regarding its own server session (content.883ade9e.js:20005).

Detection consequence: Eliminates remote cloud-replay hazards entirely. No external server generates mismatched browser fingerprints (e.g., APFC/DNA), and no concurrent sessions appear from unfamiliar datacenter IPs.

Step 7 — Zero Authenticated LinkedIn API Calls

/voyager/           → 0 matches
GraphQL             → 0 calls
credentials:include → 0 matches
csrf-token          → 0 matches
Enter fullscreen mode Exit fullscreen mode

Detection consequence: Eliminates out-of-order request-map anomalies. The extension never requests internal profile records in isolation from human page visits.

Step 8 — Native Telemetry Preserved

webRequest              → absent
declarativeNetRequest   → absent
telemetry_endpoints: []
Enter fullscreen mode Exit fullscreen mode

Detection consequence: EasyGen does not intercept, inspect, or block LinkedIn tracking scripts, allowing platform telemetry to report normally.

Step 9 — Broad Host Permissions Grant

{
  "permissions": ["storage"],
  "host_permissions": ["https://*/*"]
}
Enter fullscreen mode Exit fullscreen mode

Detection consequence: Trust and scope consideration. The codebase communicates strictly with Supabase and app.easygen.io, injecting only on www.linkedin.com. The wildcard host grant is overly broad for its functional scope, but creates no platform-side detection footprint.

Step 10 — No Automation Infrastructure

third_party_analytics: []
telemetry_endpoints: []
captcha_solvers: []
is_multi_mode: false
has_remote_control_queue: false
uploads_action_history: false
Enter fullscreen mode Exit fullscreen mode

Detection consequence: No background workers, automated scrapers, captcha bypass modules, or external dispatch queues exist within the package.

Audit Summary: Findings & Detection Vector Matrix

Finding Code Provenance Detection / Safety Implication
AED Catalog Probe Extension ID: gbefjkkjhjcloofcbandphbododcebko Installation is visible to LinkedIn via client-side AED probes
All-Frames Script Injection all_frames: true on linkedin.com/* Spectroscopy DOM scans and page snapshots observe the UI layer
Zero Session Access No cookie permissions; li_at search returned zero Zero risk of fingerprint mismatch or foreign IP session overlap
No Internal API Use No Voyager, GraphQL, or credentialed fetch routines Zero request-map anomalies
Synthetic Event Hooks DragEvent("drop") & programmatic .click() Triggers isTrusted: false, strictly scoped to individual user clicks
Supabase Architecture Outbound sync to *.supabase.co Data privacy scope: drafts leave device; credentials stay local
Broad Host Permission "host_permissions": ["https://*/*"] Overly permissive manifest configuration; broad blast radius
Zero Automation Modules No queues, schedulers, or captcha solvers Zero automated behavior patterns or rate-limit triggers

What This Means for Your Account Safety

LinkedIn relies on cumulative anomaly scoring rather than single-event triggers. EasyGen exposes three minor signals:

  • An indexed extension ID on the AED catalog.
  • Injected DOM artifacts visible to page snapshotting.
  • Synthetic isTrusted: false share-box events.

It entirely avoids dangerous macro signals: session exfiltration, remote cloud execution, proxy rotation mismatches, background scrapers, and automated connection/messaging volume.

The Real Risk Factor: Distribution and AI Slop Policies

The primary operational risk with EasyGen is content visibility, not account restriction.

On May 20, 2026, LinkedIn announced algorithmic downranking of generic AI-generated content (claiming a 94% detection rate). Posts identified as synthetic lose distribution across second- and third-degree feeds while remaining visible to immediate connections. In July 2026, LinkedIn complemented this with a user-facing "Seems like AI slop" reporting tool.

EasyGen intentionally avoids hands-off auto-posting routines for this reason: unedited, automated AI content suppresses algorithmic reach.

Final Architecture Comparison

EasyGen deserves credit for architectural discipline: its extension never captures your LinkedIn session or offloads authentication tokens to a vendor cloud.

For users comparing this to lead-generation stacks, remember that tools operate on different layers:

If you are running active outreach, messaging, or scraping, browser extensions carry higher exposure due to DOM manipulation and AED probes.

Desktop engines like Linked Helper address this by running standalone outside Chrome extensions, preserving local session custody on your OS or private VPS with built-in proxy quality verification.

EasyGen stays strictly in its lane: it writes post drafts locally, syncs them to its private database, and leaves platform-level account actions entirely in your hands.

Full line-by-line code teardown and technical references here.

Top comments (0)