Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Labubu Cursor - Custom Cursor for Chrome

aflignmhioblicjchbebbbafecmakfbb
Risk Score
6.25
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Entertainment
Installs 217
Rating
Last updated 2025-07-09 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall + install URL hijacks redirect to gameograf.com monetization UTM URLs — monetization shell pattern.
  • Privacy policy is Google's own policy, not scoped to this extension; admits data collection & 3rd-party sharing.
  • scripting + *://*/*ost permissions allow arbitrary JS injection on all sites with no CSP safeguard.
  • Small install base (217) with HIGH-tier permissions signals tail-attack-surface risk.
  • Maintenance concern: 14 months since update with broad host access.

Evidence

  • install_url_hijack + uninstall_url_hijack manifest Both onInstalled and onUninstall redirect to gameograf.com with UTM params — monetization shell fingerprint.
  • privacy_policy_generic store Privacy policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • broad_host_access + scripting manifest host_permissions *://*/* paired with scripting = can inject JS into every site visited.
  • dom_sink_innerhtml_userctrl crx Two JS files contain innerHTML sinks with variable input; no CSP to mitigate DOM-XSS risk.
  • install_perm_anomaly api 217 installs + high-tier permissions — small_install_high_perm=true, tail_attack_surface=true.
  • developer_name_missing store developer_name is empty string; no 'Offered by' display for accountability.
  • months_since_update store 14 months since last update; 6-12mo band scores +3.5 but 12-24mo band scores +6.0.
  • verified_publisher store verified_publisher=true; applies -1.0 cap per 0c (monetization redirect hits v3.5E condition).

Permissions Breakdown

  • storage low Standard key-value storage; low risk alone.
  • unlimitedStorage low Extends storage quota; low risk alone.
  • scripting high Allows JS injection into pages; HIGH when paired with *://*/*ost access.
  • *://*/*ost permission high Broad host access across all URLs; enables reading/modifying any page content.

Pillar Scores

Permissions7.00
Reputation5.50
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 10:32
Listing SHA 7f656e936714…
Force block — not fired
Score recovered no
Elapsed