Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Writecream - AI-powered writing assistant

aabfjmnamlihmlicgeoogldnfaaklfon
Risk Score
6.03
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category AI
Installs 6,000
Rating 4.9
Last updated 2023-09-15 (33 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@writecream.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension (generic site policy).
  • Extension is 33 months stale — critical maintenance gap for an AI tool with cookies + <all_urls>.
  • cookies permission + content_scripts on <all_urls> creates broad session-token exfiltration surface.
  • Brand impersonation signal: YouTube mentioned in description by unverified owner.
  • 12 external JS hosts contacted including social/reference sites — geo-diversity 4 countries with no CSP.

Evidence

  • privacy_policy_generic api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • maintenance_stale store Last updated Sep 2023; 33 months since update → +8.5 maintenance score.
  • cookies_all_urls manifest cookies permission + content_scripts <all_urls>; ×1.2 amplifier applied → permissions 6.5.
  • brand_impersonation store brand_mention.is_impersonation=true (YouTube); verified_publisher and featured → +1.0 reputation.
  • no_csp crx content_security_policy is null (MV3 default applies, no custom CSP declared).
  • geo_diversity crx 4 JS host countries (CA,DE,IN,US); category AI not in exemption list → +1.5 network.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; but stale 33mo caps discount to -1.0 (v3.5 inv 0c).
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; small install base with high-perm profile → +1.0 webstore.

Permissions Breakdown

  • storage low Stores local extension data; low standalone risk.
  • cookies high Can read/write cookies; paired with content_scripts <all_urls> raises exfil risk.
  • tabs medium Access to tab URLs and metadata across all sites.
  • content_scripts <all_urls> high Script injected on every page; broad reach amplifies cookies risk.
  • host_permissions: https://www.writecream.com/*, https://app.writecream.com/* low Scoped to developer-owned domains; justified for AI backend calls.

Pillar Scores

Permissions6.50
Reputation4.50
Network5.50
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:14
Listing SHA 99bd5ad4e79a…
Force block — not fired
Score recovered no
Elapsed 27.5s