Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Octopus - All-in-One LinkedIn Automation

afahlliooeebnifondmbhcaghcapepbm
Risk Score
4.75
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 70,000
Rating 4.3
Last updated 2026-03-25 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@octopuscrm.io
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false + data_collection=true + third_party_sharing=true → D-clause triggers +10.0 privacy pillar.
  • install_url_hijack and uninstall_url_hijack both true; onInstalled/onUninstalled redirect to unspecified 3rd-party URLs.
  • LinkedIn automation scrapes and transmits professional data to octopuscrm.io, zapier.com, make.com, and Firebase — broad external data flow.
  • Brand mention of 'linkedin' flagged as impersonation (confirmed_owner=false); may violate LinkedIn ToS and mislead users.
  • No developer name listed; privacy policy does not scope disclosures to this specific extension's data practices.

Evidence

  • privacy_policy_generic_broad api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D: +10.0 privacy.
  • install_and_uninstall_url_hijack store install_url_hijack=true, uninstall_url_hijack=true; targets null but flags are set — +2.0+3.0 webstore.
  • brand_impersonation_linkedin store brand_mention.is_impersonation=true, confirmed_owner=false, not verified_publisher per rubric gate → +2.0 reputation.
  • verified_publisher store verified_publisher=true → -3.0 reputation; no 0c cap triggers (no stale/CVE/monetization hits).
  • multiple_external_data_endpoints manifest Host perms include zapier.com, make.com, firebaseio.com, googleapis.com, cloudfunctions.net — 5+ distinct registrable domains.
  • test_project_cloud_function manifest host_permission includes us-central1-test-proj-7d39d.cloudfunctions.net; 'test-proj' suggests unpolished infra.
  • no_developer_name store developer_name is empty string; reduces accountability signal (+1.0 reputation).
  • cve_findings_clean crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0; no malicious code signals detected.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; medium risk for automation tool.
  • notifications low Show desktop notifications; low direct data risk.
  • history medium Read browsing history; sensitive personal data exposure.
  • scripting medium Inject scripts into pages; scoped to linkedin.com via content_scripts.
  • offscreen low Offscreen document support; low standalone risk.
  • host:linkedin.com/* medium Scoped to LinkedIn; expected for stated automation function.
  • host:api.octopuscrm.io/* medium Sends data to developer's own backend; LinkedIn data exfiltration surface.
  • host:hooks.zapier.com/* medium Third-party automation webhook; user data may flow to Zapier.
  • host:*.make.com/* medium Third-party automation platform; another external data path.
  • host:*.firebaseio.com/* medium Firebase real-time DB; potential data storage for scraped LinkedIn data.
  • host:www.googleapis.com/* low Google APIs; broad but commonly used for auth/storage.
  • host:cdnjs.cloudflare.com/ajax/libs/raphael/* low CDN for Raphael.js library; scoped path reduces risk.
  • host:us-central1-test-proj-7d39d.cloudfunctions.net/* medium Cloud function endpoint with 'test-proj' name; unclear production status.

Pillar Scores

Permissions4.50
Reputation5.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA 10f9a1f4d335…
Force block — not fired
Score recovered no
Elapsed 28.4s