Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Enhanced GitHub

anlikcnbgdeidpacdbdljnabclhahhmd
Risk Score
4.92
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 40,000
Rating 4.5
Last updated 2024-06-03 (24 months ago)
Manifest version MV3
CSP present ✅ yes
Developer varun2902@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; data collection and 3rd-party sharing admitted without context.
  • Brand impersonation: 'github' mentioned in name by unverified gmail developer who is not confirmed GitHub owner.
  • Developer uses free-webmail (gmail) with no business domain; accountability is limited.
  • webRequest on all GitHub traffic gives broad traffic-observation capability with 24-month stale codebase.
  • Extension stale at 24 months; borderline zombie risk as MV3 + no CVEs partially mitigates.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
  • brand_impersonation store brand_mention.is_impersonation=true for 'github'; confirmed_owner=false; developer is gmail user.
  • free_webmail_developer store Developer email varun2902@gmail.com; no business domain; Reputation base elevated.
  • webRequest_permission manifest webRequest declared; scoped to *.github.com/* only; DeveloperTools category partially justifies.
  • maintenance_stale store Last updated June 2024; months_since_update=24; Maintenance +6.0.
  • description_mismatch store Promises download but lacks 'downloads' permission; mismatches non-empty → Webstore +2.0.
  • featured_by_google store is_featured_by_google=true; applies -2.0 Reputation discount (featured badge).
  • clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, cve_findings_raw empty; Code Quality=0.0.

Permissions Breakdown

  • storage low Stores user preferences locally; minimal risk.
  • webRequest high Can observe all network requests on github.com; elevated capability.
  • webNavigation medium Monitors navigation events; needed for SPA routing on GitHub.
  • *://*.github.com/* medium Scoped host access to GitHub only; justified for stated function.

Pillar Scores

Permissions3.50
Reputation6.50
Network2.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA ae0998abc96f…
Force block — not fired
Score recovered no
Elapsed 20.5s