Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Silk - Privacy Pass Client

ajhmfdgkijocedmfjonnpjfojldioehi
Risk Score
3.76
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PrivacyTool
Installs 300,000
Rating 2.3
Last updated 2024-04-02 (29 months ago)
Manifest version MV3
CSP present ❌ no
Developer ask-research@cloudflare.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Stale: 26 months since last update; <all_urls>+webRequest surface unmaintained for >2 years.
  • Privacy policy URL points to Chrome Web Store listing page, not a real policy; retention undisclosed.
  • Low rating (2.3) may reflect user-facing reliability issues or trust concerns.
  • No CSP on MV3 extension with <all_urls>+webRequest; any future compromise has broad reach.
  • third_party_sharing flagged true in policy classification with no scope binding to this extension.

Evidence

  • developer_identity store Developer is Cloudflare Research (cloudflare.com); recognized org but no verified-publisher badge on store.
  • maintenance_stale store Last updated April 2 2024; 26 months since update triggers +6.0 maintenance score.
  • privacy_policy_invalid store Privacy policy URL is the extension's own store listing, not a real policy document.
  • host_permissions_broad manifest <all_urls> paired with webRequest grants observation of all HTTP traffic.
  • low_rating store Rating 2.3 — below 3.0 threshold; no review red-flags matched in structured scan.
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score 0.0, code_findings_raw empty — clean scan.
  • js_external_hosts crx 3 external hosts all under research.cloudflare.com subdomains — dev-controlled.
  • triple_stale_fingerprint store >24mo stale + MV3 (no MV2 penalty) + no CVEs; v2 calibration +2.0 webstore applied.

Permissions Breakdown

  • declarativeNetRequest medium Can block/modify network requests; scoped to rule-sets, lower risk than webRequest.
  • storage low Persists extension state; no direct data exfil path.
  • tabs medium Access to tab URLs and metadata across all open tabs.
  • webRequest high Observe all HTTP requests across all URLs; combined with <all_urls> is broad.
  • <all_urls> high Host permission covering every site; wide capability surface for webRequest.

Pillar Scores

Permissions5.50
Reputation3.00
Network3.50
Webstore2.00
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedna89f0a5bdp727562726963xsx 4.61 Medium review 2026-09-02
v3.6 3.76 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA 455250455232…
Force block — not fired
Score recovered no
Elapsed 22.8s