Chrome's built-in Gemini reviewed: how Skills stacks up against AI sidebar extensions
Chrome Gemini Skills now does what AI sidebar extensions charge for. I compared permissions, security records, and privacy to decide which one to trust.

Somewhere between your last two Chrome updates, the browser quietly absorbed the feature you installed an AI sidebar for. Gemini in Chrome can now summarize the page you're on, and since April it can save your prompts as one-click "Skills" that run across multiple tabs — the exact pitch half the AI extensions in the Chrome Web Store have been selling for two years.
So the question a lot of you are sitting on: do you still need that AI sidebar extension at all? I don't think there's one answer, but there is data. I compared the two options on the three things that actually matter — what they can access, how the security record of each side looks, and where the text of every page you summarize ends up.
One honest caveat up front: this review is built on Google's launch materials from April 2026 and the security research published this year, and rollouts move fast. Check what your own Chrome shows before treating any availability detail as current.
Quick verdict
- For light page-AI in Chrome — summarize, rewrite, reusable prompts — the built-in Gemini is now the lower-risk default. No install, no permission grant, no new entry in your extension list, and it can't be a fake clone of itself.
- The extension category measurably carries more risk. LayerX's 2026 report found AI extensions are 60% more likely than average to contain a known CVE, and nearly six times more likely to have quietly expanded their permissions in the past year.
- Built-in doesn't mean bulletproof. The Gemini panel itself was a privilege-escalation target (CVE-2026-0628, patched), and anything you show Gemini goes to Google, tied to your account.
- Extensions still win when you want a non-Google model, a non-Chrome browser, offline behavior, or a deep integration — like exporting study notes to Notion or Obsidian.
- Whatever you pick, audit what's already installed. Most people are running two or three AI sidebars from "just trying it" season. One is a choice; three is an attack surface.
What Skills actually is
Google launched Skills in Chrome on April 14, 2026, on desktop Mac, Windows, and ChromeOS — TechCrunch covered the launch when it landed. The idea is simple: when you write a prompt worth keeping, you save it straight from chat history and re-run it later with / or + in the Gemini sidebar — on the current page plus any other tabs you select. Google ships a pre-built library covering productivity, shopping, recipes, and budgeting.
Two details matter for this comparison. First, before a Skill takes a high-risk action — sending an email, adding a calendar event — it asks you to confirm. Second, at launch it required a Google account sign-in and an English (US) browser language, and Google's announcement leans hard on the platform argument: "Skills benefit from Chrome's layered protections, including automated red-teaming and auto-update capabilities".
That's the pitch, and it's aimed squarely at the AI sidebar market. Save a reusable action, run it on the page, apply it across tabs — that entire value proposition now ships in the browser.
The security record: extension side
Here's why I'm not neutral about this. LayerX's 2026 Browser Extension Security Report profiled the AI extension category and the numbers are ugly across the board:
- 1 in 6 enterprise users now runs at least one AI extension
- AI extensions are 60% more likely than the average extension to contain a known CVE (16.3% vs 10.8%)
- They're 3× more likely to have access to cookies — the ones holding your session tokens
- 2.5× more likely to hold scripting permissions that can inject code into pages
- Nearly 6× more likely to have increased their permissions over the past year
That last one is the sleeper. When you approved the extension, you approved a snapshot. LayerX's published analysis found permission drift is the category norm, not the exception — and users almost never notice an already-trusted tool gaining new reach.
Then there's the clone problem. Because "AI assistant" is the hottest label in the store, it's also the best camouflage. I covered the AiFrame campaign's 30 fake AI extensions that scraped Gmail from 300K users, and fake variants keep showing up in the category. A built-in feature has no clones. An installed one competes with a dozen lookalikes wearing its name.
The security record: native side
Now the fair part. Native doesn't mean invulnerable — it means differently vulnerable.
When Chrome bolts a privileged AI panel into the browser, that panel becomes a target for everything else already installed. Palo Alto Networks' Unit 42 documented exactly that with CVE-2026-0628: a flaw that let extensions with basic permissions hijack the new Gemini panel, with a potential path to camera, microphone, and local file access. Google patched it — I broke the whole class of problem down in my piece on AI panel hijacking — but the direction of the risk is worth remembering: privileged browser AI concentrates power somewhere attackers want to reach.
Skills also does agentic things — running across tabs, drafting emails, touching your calendar. The confirmation prompts are the right instinct, but confirmations only work if the human clicking "yes" knows what they're approving. Researchers have already shown extensions can drive AI assistants with synthetic clicks and inject instructions into AI conversations they have no business touching — the man-in-the-prompt pattern. The more your browser's AI can do, the more valuable it is to steer.
So: extensions carry a worse statistical profile, and native AI carries a smaller but sharper concentration risk. Neither option is "install and forget."
Privacy: where your page content goes
This is the axis where the comparison flips for a lot of readers.
Native: everything you ask Gemini about, it reads — and that content goes to Google, tied to the signed-in account Skills requires, synced across your devices. If you're already living in Google's ecosystem, that's the deal you accepted years ago. If you specifically don't want the company that indexes the web reading your bank statements and internal docs through a sidebar, built-in Gemini is not a privacy win. It's a convenience win.
Extensions: the independent record here is worse than the inconvenience math. The UC Davis team behind the GenAI browser assistant study tested nine popular AI assistants — Monica, Sider, Merlin, MaxAI, HARPA.AI, and others — and found, per the researchers, one extension transmitted the full content of an IRS form including a Social Security Number to third-party servers, another collected page content passively whether or not you used it, and two built persistent behavioral profiles across sessions. I went through all nine findings in my breakdown of the study.
And that study tested the legitimate ones. LayerX separately identified 82 Chrome extensions that openly reserve the right to sell your data in privacy policies nobody reads — and found 71% of Chrome Web Store extensions have no privacy policy at all.
So which should you use?
My decision framework, after going through both records:
Use built-in Gemini/Skills if you're on Chrome, signed in anyway, and your use is the common case: summarize this page, rewrite this email, keep five prompts you reuse. The marginal risk over the Chrome you already run is close to zero, and the marginal risk of yet another sidebar extension is not.
Use the plain web app — chatgpt.com, claude.ai, gemini.google.com in a tab — when the content is sensitive enough that you want to decide exactly what the model sees. Copy-paste is the most privacy-preserving AI workflow ever invented, and it's underrated.
Keep an extension only when it does something native can't: a non-Google model in the sidebar, Firefox/Safari/Edge support, offline behavior, or a real workflow integration — the study-notes tooling I compared in the YouTube summarizer review is a good example of the last one. And if you keep one, make it earn the permissions:
- Site access to "On click," not "On all sites." You invoke an AI tool deliberately; it doesn't need to read your banking tab in the background. I explained what "read all data on all websites" really allows if you want the full picture.
- Check its permission history. The 6× drift stat means "it was fine at install" proves nothing. Its catalog page shows what it asks for now.
- Prefer a real vendor or open source. For a tool that reads every page you visit, "trust me" should cost it points.
- Delete the duplicates. One vetted AI extension is a tool. Three half-remembered ones are an inventory problem.
Before you install anything new, look it up in the Extenshi catalog — declared permissions and scanner findings on one page instead of a manifest you have to decode. And for what's already sitting in your browser, you can scan your installed extensions and get a report per tool.
Final recommendation
For the default reader — Chrome user, wants page summaries and a few saved prompts — the browser won. Use built-in Gemini, skip the sidebar install, and you've removed one whole category of clone campaigns, permission drift, and study-documented data leaks from your life.
Keep exactly one AI extension if, and only if, it does something Google's version structurally can't. Vet it like it reads every page you visit — because that's the job description.
See what your AI extensions actually hold → security report in the Extenshi catalog. Prefer a terminal? npx @extenshi/guard scan checks every extension already installed in your browsers, no account needed (docs here).
Sources
- Turn your best AI prompts into one-click tools in Chrome — Google (official announcement)
- Google adds AI Skills to Chrome to help you save favorite workflows — TechCrunch
- The LayerX Browser Extension Security Report 2026
- The AI Tool in Your Browser Is Probably the Biggest Security Risk You're Not Thinking About — LayerX Security
- Your Extensions Sell Your Data (And It's Perfectly Legal) — LayerX Security
- Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel — Palo Alto Networks Unit 42
- GenAI browser assistant extension tracking study (Xie et al.) — USENIX Security
This article is based on publicly available security research and news reporting. Extenshi does not independently verify all claims made by third-party researchers. References to specific companies or products reflect the findings of cited sources and do not constitute accusations of intentional wrongdoing. If you believe any information is inaccurate, please contact us at [email protected].
Related Articles
AI browser assistant extensions explained: what nine popular add-ons were actually doing with your data
AI browser assistant data collection can sweep up your SSN and medical data — UC Davis tested 9 GenAI extensions and found just that. Here's what they access.
Browser AI panel hijacking: how to check which of your Chrome extensions can abuse elevated privileges
Chrome extension privilege escalation is real: CVE-2026-0628 let extensions with basic permissions reach your camera, mic, and files via the Gemini panel.

The click nobody made: how to check which extensions can drive your AI assistant
Understand Claude for Chrome security risks from synthetic clicks. Learn the reported attack conditions and how to isolate your AI tools from other extensions.
AI extension data collection explained: what your Chrome AI tools can really access
AI extension data collection is real: 52% of AI Chrome extensions collect user data. Here's what scripting permissions let them see, and how to check yours.