The extension is triggering https://www.crowdsec.net/ protection
This extension checks several frequently used URLs (like /feed.xml, /rss.cml) to get an RSS feed, and this behavior of 'scanning' multiple URLs is considered potentially malicious. - source: https://passerelles.encommun.io/c/soutien-en-commun/m?m=20753#m_20753
The extension is triggering https://www.crowdsec.net/ protection