Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Open in Onion Browser

balknnpjeohaolphkfhghbaapifbokik
Risk Score
6.54
Risk Level: High
Recommendation: 🚫 BLOCK
Category PrivacyTool
Installs 1,000
Rating 1.0
Last updated 2023-10-15 (32 months ago)
Manifest version MV3
CSP present ❌ no
Developer joue.quroi@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging with unrecognized publisher allows arbitrary OS-level code execution.
  • Content scripts injected on *://*/* give page-read access on every site visited.
  • Privacy policy is Google's generic policy — completely unscoped to this extension.
  • Extension stale 32 months (last updated Oct 2023); abandoned/unpatched risk.
  • Gmail-only developer identity with 1-star rating; no verified business accountability.

Evidence

  • nativeMessaging_unrecognized crx native_messaging_check.publisher_recognized==false; companion app publisher unknown, arbitrary host code exec possible.
  • content_scripts_broad manifest content_scripts_matches=['*://*/*'] injects into every page, paired with nativeMessaging.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_extension store Last updated Oct 2023; months_since_update=32; effectively abandoned.
  • free_webmail_dev store developer_email=joue.quroi@gmail.com; no verified business domain.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target undisclosed, redirects on uninstall.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 1000 installs with HIGH-tier permission (nativeMessaging).
  • js_external_hosts crx Extension contacts api.github.com and github.com; no CSP; purpose not explained in listing.

Permissions Breakdown

  • storage low Local preference storage; low standalone risk.
  • activeTab low Transient access to current tab on user action only.
  • contextMenus low UI menu item; no data access on its own.
  • nativeMessaging high Bridges to host OS; allows arbitrary code exec via unrecognized companion app.
  • content_scripts *://*/* high Broad injection into every page combined with nativeMessaging is high-risk exfil surface.

Pillar Scores

Permissions7.00
Reputation8.00
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA a7a0851cb354…
Force block — not fired
Score recovered no
Elapsed 20.3s