Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Export Twitter Followers

amflfbkcoeanhfcdcbebeimpjnoebakn
Risk Score
4.91
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 8,000
Rating 4.8
Last updated 2026-04-26 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer jfl913@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies permission + broad twitter.com/x.com host access enables harvesting of auth session cookies
  • Privacy policy fetched but admits data collection and third-party sharing without scoping to this extension — worst-case policy
  • Developer uses free Gmail address (jfl913@gmail.com) with no verified business identity
  • Brand impersonation: extension named 'Export Twitter Followers' uses Twitter brand without confirmed ownership
  • No CSP declared on MV3 extension — no additional mitigation against injected scripts

Evidence

  • cookies + broad host access manifest cookies permission paired with *://*.twitter.com/* and *://*.x.com/* — full auth-cookie read capability.
  • privacy policy scope mismatch crx Policy fetched (17455 chars), scope_extension=false, data_collection=true, third_party_sharing=true — v3.5(D) triggers +10.0.
  • brand impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, developer_domain=gmail.com — +2.0 reputation.
  • free webmail developer store Developer email jfl913@gmail.com; no verified business; free-webmail+no-verified-domain risk cluster.
  • is_featured_by_google store Extension carries Google Featured badge — applied -2.0 reputation discount (impersonation reduces to +1.0 net).
  • no CSP manifest content_security_policy is null on MV3; no additional network policy enforcement.
  • operator_cluster dev_email siblings=2 api sibling_count by dev_email dimension = 2 (compound=0); same email linked to other extensions.
  • code quality clean crx code_findings_raw empty, obfuscation_score=0.0, 4 JS files scanned — no malicious patterns detected.

Permissions Breakdown

  • cookies high Can read/write cookies; paired with twitter.com/x.com host access allows harvesting auth cookies.
  • storage low Local extension storage only; low standalone risk.
  • identity low OAuth token access; risk depends on scopes requested at runtime.
  • *://*.twitter.com/* high Broad host access to Twitter — combined with cookies enables full account data access.
  • *://*.x.com/* high Broad host access to X.com — same risk surface as twitter.com.

Pillar Scores

Permissions6.00
Reputation7.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA fd687cb92e79…
Force block — not fired
Score recovered no
Elapsed 23.9s