⚠ Medium — Risky tool Analyzed 2026-10-02 · UTC
A security-hygiene observation, not a malware finding. This advisory documents dangerous security practices in a legitimate-purpose tool — for example transmitting credentials over plaintext HTTP, heavy code obfuscation, or automatic global installs. It is not a claim of theft, backdoor or malicious intent: the tool does what it advertises, and the risk falls on its own users and their data. It is published so operators can make an informed decision before installing or deploying it.
Advisory · CLR-2026-3066

akiflow-toolkit — scrapes your Akiflow session out of Chrome's credential store

A third-party Akiflow tool decrypts Chrome's cookies/IndexedDB to lift your Akiflow token instead of using OAuth. First-party use only — no exfiltration — but a risky technique.

Risky toolMediumnpm
What it is

akiflow-toolkit is a third-party, open-source MCP/CLI tool for the Akiflow productivity app (repo github.com/kty1965/akiflow-toolkit, binary af). To talk to Akiflow on the user's behalf it uses a ChromeCookieReader plus Chrome's IndexedDB/leveldb stores to decrypt and lift the user's existing Akiflow JWT / refresh token straight out of the browser.

Crucially, that token is then used only against Akiflow's own first-party endpoints (api.akiflow.com, web.akiflow.com/oauth/refresh, /auth/login). We found no third-party exfiltration and no remote operator — so this is a Risky tool, not a credential stealer.

Why it is risky

Decrypting the browser's credential store is an invasive way to obtain a token. A proper integration uses an OAuth flow where the user explicitly grants access; reading cookies/IndexedDB instead means a third-party tool is handling your decrypted session secret directly.

The capability is also broad: the same ChromeCookieReader machinery can read any site's cookies, so a future version (or a compromise of this package) could repoint it. The risk is to the tool's own users — nothing here steals data today, but the technique is one worth being aware of before installing.

Behaviours to be aware of
🍪ChromeCookieReader + Chrome IndexedDB/leveldb → decrypts and lifts the Akiflow JWT/refresh token
✅Token used first-party only: api.akiflow.com, web.akiflow.com/oauth/refresh, /auth/login
✅No third-party exfiltration, no remote operator/relay
📦Open source: github.com/kty1965/akiflow-toolkit
If you use it
#ActionPriority
1 Prefer an official Akiflow OAuth integration over a third-party tool that decrypts your browser's cookie store. Recommended
2 If you run it, review the pinned version and watch the ChromeCookieReader usage across updates — the capability can read any site's cookies, not just Akiflow's. Recommended

Explicitly not malware: open source, first-party-only network, no exfiltration and no remote operator (contrast CLR-2026-3064). Catalogued as a Risky tool so users understand the browser-cookie-scraping technique; excluded from the OSV outputs by design.