Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PubMed in Perplexity

bcgbinkgdoalmnblbodopdaogieejcpi
Risk Score
3.49
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 2,000
Rating 5.0
Last updated 2025-12-31 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer matsui.kentaro@ncnp.go.jp
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension mentions 'Perplexity' but developer is not a confirmed owner of that brand.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores maximum under v3.5 rule D.
  • Developer domain ncnp.go.jp does not resolve, limiting accountability.
  • No CSP defined (MV3 provides strict default, but no custom scoping for external hosts felo.ai, openevidence.com, perplexity.ai).
  • Small install base (2,000) with unverified publisher and non-resolving developer domain raises tail-risk concern.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'perplexity'; confirmed_owner=false.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • developer_domain_not_resolving api threat_intel.developer_domain_info.resolves=false for ncnp.go.jp.
  • external_hosts crx js_external_hosts: felo.ai, www.openevidence.com, www.perplexity.ai — 3 distinct domains.
  • no_permissions manifest permissions=[], host_permissions=[], content_scripts_matches=[] — minimal declared capability.
  • maintenance store months_since_update=6, in 3-6mo band → +1.5.
  • no_cve_no_obfuscation crx cve_findings_raw=[], obfuscation_score=0.0, code_findings_raw=[] — no malicious code detected.
  • no_bad_hosts_no_affiliate api bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no threat-intel hits.

Pillar Scores

Permissions0.00
Reputation7.00
Network0.00
Webstore2.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 637bf7c9a3fc…
Force block — not fired
Score recovered no
Elapsed 18.6s