Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Avengers Cursor ★ Custom Cursor for Chrome™

ajcnllagebcaahcdfbappndlmhmpdhif
Risk Score
5.09
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 451
Rating 5.0
Last updated 2025-11-30 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer afraezgi4@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to yowgames.com (utm-tracked) — classic monetization/traffic shell pattern.
  • Install URL hijack to yowgames.com — onInstalled redirects user to 3rd-party site.
  • Privacy policy is generic (yowgames.com), not scoped to this extension; admits data collection and third-party sharing.
  • Developer uses free Gmail with no verified identity; domain identity cannot be confirmed.
  • Content scripts run on every URL (*://*/*) giving persistent access to all page content.

Evidence

  • uninstall_url_hijack manifest setUninstallURL → https://yowgames.com/avengers-cursor with UTM params; monetization redirect on remove.
  • install_url_hijack manifest onInstalled opens https://yowgames.com/avengers-cursor with UTM params; 3rd-party traffic grab.
  • content_scripts_broad manifest content_scripts_matches: [*://*/*] — runs on every site the user visits.
  • privacy_policy_generic store Policy at yowgames.com: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email afraezgi4@gmail.com; no verified publisher; identity unverifiable.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
  • js_external_host_yowgames crx js_external_hosts includes yowgames.com alongside chrome.google.com.
  • cve_findings_empty crx No CVEs found; jquery 3.6.0 bundled (no known CVEs at this version in findings).

Permissions Breakdown

  • storage low Stores cursor preference settings locally; low standalone risk.
  • content_scripts *://*/* medium Injects JS/CSS on every page visited; broad surface for cursor injection but also data access.

Pillar Scores

Permissions1.80
Reputation7.00
Network0.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:21
Listing SHA 6f6ed4f71767…
Force block — not fired
Score recovered no
Elapsed