Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Magic Actions for YouTube™

abjcfabbhafbcdfjoecdgepllmpfceif
Risk Score
4.02
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 600,000
Rating 4.7
Last updated 2025-10-30 (10 months ago)
Manifest version MV?
CSP present ❌ no
Developer support@mixesoft.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection AND third-party sharing but is not scoped to this extension — scores maximum privacy risk.
  • Brand impersonation: extension name uses YouTube™ trademark; developer (mixesoft.com) is not YouTube/Google.
  • Manifest source is html_fallback — exact permission surface unknown, cannot confirm declared scope.
  • No developer name listed in store; only email present, reducing accountability.
  • 700K installs create large blast radius if policy/ownership changes adversely in future.

Evidence

  • privacy_policy_classification api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy per v3.5 rule D.
  • brand_impersonation store brand_mention.is_impersonation=true; YouTube trademark in title; developer is mixesoft.com, not Google/YouTube.
  • verified_publisher store verified_publisher=true; provides reputation discount but capped by monetization/stale checks (none triggered here).
  • manifest_source_fallback store manifest_source=html_fallback; js_files_scanned=0; actual permissions and code surface unverifiable.
  • developer_name_missing store developer_name is empty string; reduced accountability signal.
  • maintenance store months_since_update=8; falls in 6-12mo band → +3.5 maintenance score.
  • operator_cluster api sibling_count=0 by compound fingerprint; dev_email dimension shows 2 but compound=0, no cluster penalty applied.
  • threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves and is not throwaway.

Permissions Breakdown

  • manifest_source:html_fallback medium Manifest parsed from HTML fallback; exact permissions unknown — scored conservatively.

Pillar Scores

Permissions1.00
Reputation5.50
Network0.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%55%33%54%73%28%39%38%37%38%34%29%22 2.43 Low review 2026-08-05
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 4.10 Medium review 2026-08-05
<%={{={@{#{${dfb}}%> 2.29 Low review 2026-08-05
v3.6&n973769=v949335 2.52 Low review 2026-08-05
v3.6"onmouseover=cNZD(92602)" 4.08 Medium review 2026-08-04
v3.6&n916722=v982229 4.22 Medium review 2026-08-04
%76%33%2E%36%39%35%38%30%22%28%29%3B%7D%5D%39%36%39%39 2.34 Low review 2026-07-29
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%61%43%53%36%28%39%36%31%31%34%29%22 5.22 Medium review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 2.43 Low review 2026-07-29
<th:t="${dfb}#foreach 2.56 Low review 2026-07-29
dfb[[${98991*97996}]]xca 3.54 Low review 2026-07-29
bfg9241<s1﹥s2ʺs3ʹhjl9241 4.03 Medium review 2026-07-29
v3.6&n935403=v950073 4.04 Medium review 2026-07-29
v3.6 4.02 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA 26c8f2676220…
Force block — not fired
Score recovered no
Elapsed 19.7s