Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ChatGPT for StackOverflow

apjhekoaogdimcgiihoncakocdddhmlk
Risk Score
6.15
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category AI
Installs 1,000
Rating 4.0
Last updated 2023-03-01 (39 months ago)
Manifest version MV3
CSP present ❌ no
Developer shobrookj@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension name references both ChatGPT and StackOverflow without verified ownership of either brand.
  • Privacy policy is Google's own generic policy — not scoped to this extension, admits data collection and third-party sharing.
  • Extension is 39 months stale (zombie) with no CSP, raising supply-chain hijack risk.
  • Developer uses free Gmail address with no verified business domain or publisher badge.
  • Mixpanel analytics (api-js.mixpanel.com, cdn.mxpnl.com) bundled and contacting external hosts with no disclosed data handling.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands=['stackoverflow','chatgpt']; confirmed_owner=false; dev domain=gmail.com
  • generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true
  • staleness store last_updated=March 1 2023; months_since_update=39; >36mo zombie threshold triggered
  • no_csp manifest content_security_policy=null on MV3 extension; csp_present=false
  • mixpanel_analytics crx js_external_hosts includes api-js.mixpanel.com and cdn.mxpnl.com; telemetry with no disclosed retention
  • free_webmail_dev store developer_email=shobrookj@gmail.com; no business website; not verified publisher
  • ai_page_content_processing manifest AI extension injecting into SO question pages and forwarding content to chat.openai.com
  • is_featured_by_google store is_featured_by_google=true; partial trust signal, does not override impersonation/staleness risks

Permissions Breakdown

  • storage low Stores local extension data; no user-data exfil risk on its own.
  • https://*.openai.com/ (host_permission) medium Allows requests to OpenAI API; scoped to single domain, matches stated function.
  • content_scripts on stackoverflow.com medium Injects JS into SO question pages; scoped narrowly to questions path.

Pillar Scores

Permissions2.30
Reputation7.50
Network4.00
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 29c6a027b247…
Force block — not fired
Score recovered no
Elapsed 20.9s