Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Grok 4

aoemlgniakbojcecmjefonjkgnceklpg
Risk Score
5.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 10,000
Rating 4.7
Last updated 2025-12-25 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer grokaitool@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Title 'Grok 4' impersonates xAI's Grok brand; dev email is a free Gmail with no verified business identity.
  • Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
  • Extension loads content from 7 easytool.dev subdomains (ChatGPT, Grok, Gemini, DeepSeek, Perplexity) — broad external JS surface with no CSP.
  • Uninstall and install URL hijack flags set — typical monetization/tracking shell pattern.
  • Manifest name/description use i18n placeholders only; no visible developer name; classic anonymity indicators.

Evidence

  • brand_impersonation_pattern store Title 'Grok 4' + Gmail dev email grokaitool@gmail.com; not affiliated with xAI. brand_mention.is_impersonation==false but name mimics brand.
  • uninstall_install_url_hijack crx uninstall_url_hijack=true AND install_url_hijack=true; targets null but flags indicate monetization shell wiring.
  • external_js_hosts crx 7 easytool.dev subdomains contacted: chatgpt-5, chatgpt-sidebar, deepseek-ai, gemini-2, grok-3, grok-ai, perplexity-ai.
  • no_csp crx csp_present=false on MV3 extension loading 7 external JS hosts; DOM-XSS sink present.
  • privacy_policy_generic store Policy is Google's own account privacy page (scope_extension=false, data_collection=true, third_party_sharing=true).
  • free_webmail_dev_no_name store Developer email is Gmail; developer_name empty; domain_age_ct not queried due to free webmail.
  • manifest_placeholders crx manifest_name='__MSG_appName__'; manifest_description='__MSG_shortDesc__' — identity obscured.
  • dom_xss_sink crx innerHTML assignment from variable in iframe-service-C9N42zcQ.js with no CSP mitigating XSS risk.

Permissions Breakdown

  • storage low Local key-value storage; no cross-origin access.
  • sidePanel low Displays sidebar UI; no data exfil capability alone.

Pillar Scores

Permissions0.60
Reputation7.50
Network3.50
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:23
Listing SHA 161ed8b48c3f…
Force block — not fired
Score recovered no
Elapsed