Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CaveiraCards

amdebhmimbbigkdagackjdnmjnogdhic
Risk Score
3.34
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not describe this extension's data practices at all.
  • Developer name, email, install count, and last-updated date are all missing — very low accountability.
  • install_url_hijack detected: extension opens a URL on install (target unknown).
  • Two DOM-XSS innerHTML sinks found; no CSP in MV3 manifest to mitigate.
  • nubank.com.br appears in js_external_hosts but is not in host_permissions — unexplained external contact.

Evidence

  • privacy_policy_generic store Policy URL is Google Account generic policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity_missing store developer_name, developer_email all empty; verified_publisher=false, is_featured=false.
  • install_url_hijack crx install_url_hijack=true; target unknown. Extension opens a URL on install.
  • dom_xss_sinks crx innerHTML sinks in shared/anki.js and sessoes.js; csp_present=false elevates risk.
  • unexpected_external_host crx nubank.com.br in js_external_hosts but absent from host_permissions; purpose not stated.
  • maintenance_unknown store months_since_update=null; last_updated missing; cannot assess staleness.
  • localhost_host_permission manifest http://localhost:8765/* permitted — consistent with AnkiConnect but unusual for enterprise.
  • no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries detected.

Permissions Breakdown

  • storage low Stores local extension data; low risk.
  • tabs medium Can read tab URLs and metadata; moderate privacy surface.
  • notifications low Displays notifications; low risk.
  • alarms low Schedules periodic tasks; low risk.
  • offscreen low Creates offscreen documents; low risk in MV3 context.
  • host:tecconcursos.com.br low Narrow host permission matching stated function (Brazilian exam platform).
  • host:grancursosonline.com.br low Narrow host permission matching stated function.
  • host:qconcursos.com low Narrow host permission matching stated function.
  • host:deltinha.com.br low Narrow host permission matching stated function.
  • host:app.caveira.com low Developer's own platform; narrow scope.
  • host:lms.focusconcursos.com.br low Narrow host permission matching stated function.
  • host:localhost:8765 medium Localhost access suggests AnkiConnect integration; unusual but documented use-case.

Pillar Scores

Permissions2.30
Reputation6.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:38
Listing SHA 1565c5ee6334…
Force block — not fired
Score recovered no
Elapsed