Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dark Mode - Night Eye

alncdjedloppbablonallfbkeiknmkdi
Risk Score
3.67
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Accessibility
Installs 300,000
Rating 4.5
Last updated 2026-08-27 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer extensions@promotino.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack redirects to nighteye.short.gy (3rd-party URL shortener); +3.0 webstore signal.
  • Broad host access (*://*/*) combined with scripting and content_scripts on all URLs; dark-mode category partially justifies.
  • 10 innerHTML DOM-XSS sinks across UI and content scripts; CSP is present but sinks remain exploitable via page-supplied data.
  • No developer name listed in store; identity pillar elevated.
  • 11 external JS hosts including imgbb.com and relayflow.promotino.com; >3 distinct registrable domains raises network concern.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL set to https://nighteye.short.gy/rdzkOC/# — 3rd-party URL shortener redirect.
  • host_permissions_broad manifest *://*/* with content_scripts on <all_urls>; scripting permission compounds reach.
  • dom_xss_sinks crx 10 innerHTML assignments from variables found across background, content, and popup JS files.
  • external_hosts_count crx 11 distinct external hosts: billing.nighteye.app, imgbb.com, relayflow.promotino.com, social platforms.
  • no_developer_name store developer_name field is empty; only email extensions@promotino.com is present.
  • is_featured_by_google store Extension carries Google Featured badge, providing partial trust signal.
  • privacy_policy_classification api Policy fetched, scoped to extension, discloses data collection, retention, and third-party sharing.
  • cve_findings_raw crx No CVEs detected in bundled JS libraries.

Permissions Breakdown

  • storage low Stores user preferences for dark mode settings.
  • contextMenus low Adds right-click menu options; low standalone risk.
  • activeTab low Scoped to current tab on user action; limited blast radius.
  • tabs medium Can read tab URLs and titles across all tabs.
  • scripting medium Injects scripts into pages; paired with host_permissions <all_urls> is significant.
  • identity medium Can obtain OAuth tokens; risk depends on scopes requested at runtime.
  • *://*/* high Broad host access on all URLs; content_scripts also on <all_urls>. Core to dark-mode function but high capability.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.50
Webstore5.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn16c8d162dp727562726963xsx 3.42 Low review 2026-09-08
<fsssiedxi&#x22;sssiedx 3.26 Low review 2026-08-14
<fsssiedxa&#x22;sssiedx 4.08 Medium review 2026-08-11
<fsssiedxa sssiedx 3.48 Low review 2026-08-11
<fsssiedxa&#x27;sssiedx 3.04 Low review 2026-08-11
fsssiedxa<sssiedx 3.51 Low review 2026-08-11
<fsssiedxf$"sssiedx 3.57 Low review 2026-08-07
%27fsssiedxg$'sssiedx 3.61 Low review 2026-08-07
<fsssiedxgfdsaxax><!--></ScRiPt>asddsssiedx 3.55 Low review 2026-08-07
<fsssiedx{$"sssiedx 3.74 Low review 2026-08-07
<fsssiedxi$'sssiedx 3.69 Low review 2026-08-07
<fsssiedxa xx psssiedx 3.28 Low review 2026-08-07
<fsssiedxa$'sssiedx 3.26 Low review 2026-08-07
<fsssiedxi xx psssiedx 3.56 Low review 2026-08-03
<fsssiedxi$"sssiedx 4.28 Medium review 2026-08-03
<fsssiedxa"sssiedx 3.63 Low review 2026-08-03
<fsssiedxa$"sssiedx 3.37 Low review 2026-08-03
<fsssiedxa'sssiedx 3.52 Low review 2026-07-28
<fsssiedxi"sssiedx 3.46 Low review 2026-07-28
fsssiedx<sssiedx 3.51 Low review 2026-07-28
<fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx 3.27 Low review 2026-07-28
<fsssiedxf&#x22;sssiedx 3.32 Low review 2026-07-28
fsssiedxx sssiedx 3.49 Low review 2026-07-28
fsssiedxx'sssiedx 2.86 Low review 2026-07-28
sssieddrubricxsx 4.11 Medium review 2026-07-28
v3.6 3.67 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA e61faa454c26…
Force block — not fired
Score recovered no
Elapsed 26.2s