Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TabLoom: Visual Tab Group Mindmap

bahegaolgkmgnjnppnlgkfedbfnnfila
Risk Score
5.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3
Rating
Last updated 2026-07-13 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer hunkiepeanut.dev@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • declarativeNetRequestWithHostAccess + <all_urls> enables network interception on every site the user visits.
  • Privacy policy is Google's generic account policy — admits data collection and 3rd-party sharing, not scoped to this extension.
  • Free-webmail developer, no verified publisher, identity unverifiable; floor reputation risk.
  • Only 3 installs with HIGH-tier permissions — tail-attack-surface anomaly.
  • External hosts include example.com and foo.bar — anomalous placeholder domains in a production CRX.

Evidence

  • declarativeNetRequestWithHostAccess + <all_urls> manifest Extension can intercept and modify all HTTP(S) requests on every site; HIGH capability mismatch for a tab visualizer.
  • Privacy policy is Google account policy store URL myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10 privacy pillar.
  • Free-webmail developer, no verified publisher store hunkiepeanut.dev@gmail.com; no business domain, no featured badge, no verified publisher status.
  • install_perm_anomaly: small_install_high_perm api Only 3 installs with HIGH-tier permissions (declarativeNetRequestWithHostAccess, <all_urls>).
  • Anomalous external JS hosts crx js_external_hosts includes example.com and foo.bar — placeholder/test domains unexpected in a production extension.
  • No CSP defined manifest csp_present=false on MV3; no additional script-src hardening beyond MV3 defaults.
  • Content scripts on <all_urls> manifest Scripts injected into every page visited; broad reach for a tab-management tool.
  • No code findings, obfuscation_score=0 crx 6 JS files scanned; no malicious signals detected in code scan.

Permissions Breakdown

  • storage low Standard local data persistence; low risk in isolation.
  • tabs medium Reads tab URLs and titles across all open tabs; broad metadata access.
  • tabGroups low Manages tab grouping; fits stated mindmap function.
  • declarativeNetRequestWithHostAccess high Can intercept/modify network requests on all URLs; high capability even if unused offensively.
  • <all_urls> (host_permissions) high Content scripts injected into every site; combined with declarativeNetRequestWithHostAccess is high risk.

Pillar Scores

Permissions6.50
Reputation8.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:22
Listing SHA 6452d474d249…
Force block — not fired
Score recovered no
Elapsed