Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Spotify Friend Activity

amlnlcdighbhfciijpnofbpphfnkmeaa
Risk Score
4.39
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 6,000
Rating 4.7
Last updated 2025-05-30 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer jack.weatherford@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension uses 'Spotify' brand name without being confirmed owner, gmail dev with no corporate identity.
  • Privacy policy fetched but scope_extension==false AND admits data_collection+third_party_sharing — triggers +10.0 per v3.5 rule D.
  • Free-webmail developer (gmail.com) with no verified business domain raises accountability concerns.
  • Policy hosted on GitHub Pages (free hosting) without extension-specific scope; third-party data sharing admitted.
  • Maintenance at 13 months since update crosses 12-24mo band (+6.0).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; brands_mentioned=['spotify'], dev domain=gmail.com.
  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
  • free_webmail_dev store Developer email jack.weatherford@gmail.com; no verified business domain; domain_age_ct not queried (free webmail).
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
  • maintenance_stale store months_since_update=13; falls in 12-24mo band (+6.0 maintenance pillar).
  • external_hosts crx js_external_hosts: chrome.google.com, github.com, guc-spclient.spotify.com, i.imgur.com, open.spotify.com (5 hosts, 3 countries).
  • no_bad_hosts_no_cve api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], cve_findings_raw=[], code_findings_raw=[] — clean scan.
  • operator_cluster_clean api operator_cluster.sibling_count=0; no related extensions under same fingerprint.

Permissions Breakdown

  • storage low Persists extension state/settings; no cross-site read capability.
  • host_permission: https://open.spotify.com/* medium Scoped to single domain; enables content script injection and request access to Spotify web player only.

Pillar Scores

Permissions1.30
Reputation7.50
Network2.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA 2f1fe357a27c…
Force block — not fired
Score recovered no
Elapsed 20.8s