Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon ASIN Copy

aohfjaadlbiifnnajpobdhokecjokhab
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 51
Rating 5.0
Last updated 2026-01-05 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer 10xprofitio@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — scores maximum privacy risk.
  • Brand impersonation signal: extension references Amazon brand but developer is unaffiliated gmail user.
  • eval() and new Function() in bundled node_modules (sucrase, source-map-js) shipped in production CRX — code execution risk.
  • innerHTML DOM-sink in src/content.js with no CSP — XSS risk on Amazon pages.
  • Free-webmail developer email (gmail) with no verified publisher status raises accountability concerns.

Evidence

  • privacy_policy_admits_collection_and_sharing_not_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (D rule).
  • brand_impersonation store brand_mention.is_impersonation=true for 'amazon'; developer domain is gmail.com, confirmed_owner=false.
  • eval_and_function_constructor_in_production_bundle crx eval() in sucrase RootTransformer and new Function() in source-map-js/tailwindcss shipped in extension CRX.
  • dom_xss_sink_no_csp crx innerHTML assignment in src/content.js; csp_present=false raises DOM-XSS risk on Amazon pages.
  • free_webmail_developer store Developer email 10xprofitio@gmail.com; not verified publisher, not featured by Google.
  • no_csp_mv3 manifest content_security_policy is null; MV3 default CSP applies but no explicit hardening declared.
  • maintenance_6_to_12_months store months_since_update=7; maps to +3.5 maintenance score.
  • low_install_count store Only 51 installs; blast radius limited but unverified developer with high-risk policy signals.

Permissions Breakdown

  • clipboardWrite medium Allows writing to clipboard; expected for ASIN copy function.
  • *://*.amazon.com/* (and 20 Amazon TLD variants) medium Broad host access scoped to Amazon domains only; matches stated function.

Pillar Scores

Permissions2.30
Reputation7.50
Network0.00
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:26
Listing SHA 88b07cd78aba…
Force block — not fired
Score recovered no
Elapsed