The extension requires the permission scope of <all_urls> which would allow the extension to grab any data from any website the user is browsing.
Is there a way to narrow the scope or documentation that can be shared with security folks of what data exactly is recorded?
Adding Teddy to the ticket a the response will be relevant to him.