Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouTube To Transcript: AI Summarizer & Chat

bcmoplgjpddohaelhnnodojbamdobbhc
Risk Score
3.34
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 60,000
Rating 4.8
Last updated 2026-03-30 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer andrej.simunaj@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail developer with no verified publisher status; unverifiable identity accountability.
  • Brand impersonation: uses 'YouTube' in name/title but dev is not confirmed YouTube/Google owner.
  • install_url_hijack: onInstalled opens a third-party URL (potential redirect/phishing on install).
  • AI extension processes YouTube page content and sends to developer backend (youtubetotranscript.com).
  • DOM-XSS sink (innerHTML) in popup.js with no CSP set; risk amplified by FIX B.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer is gmail.com, not Google/YouTube; +2.0 Reputation.
  • install_url_hijack manifest install_url_hijack=true; onInstalled opens 3rd-party URL; +2.0 Webstore.
  • free_webmail_dev store Developer email andrej.simunaj@gmail.com; no verified publisher, no org; +1.5 Reputation.
  • ai_page_content_processing store AI extension fetching YouTube transcripts and sending to developer backend; +2.5 Webstore.
  • dom_sink_innerhtml_no_csp crx innerHTML in popup.js + csp_present=false triggers FIX B: +2.0 Code Quality.
  • privacy_policy_adequate api Policy fetched, scoped to extension, data_collection+retention+3rd_party all disclosed; +1.0 Privacy.
  • maintenance_3_6mo store months_since_update=4; in 3-6mo band; +1.5 Maintenance.
  • no_cve_findings crx cve_findings_raw empty; CVE pillar=0.0.

Permissions Breakdown

  • storage low Stores local extension data; low risk.
  • activeTab low Access only to currently active tab on user interaction.
  • tabs medium Can read tab URLs and titles; moderate privacy exposure.
  • notifications low Shows desktop notifications; minimal risk.
  • alarms low Schedules background tasks; low risk.
  • identity low OAuth identity without declared scopes; low risk in isolation.
  • https://www.youtube.com/* medium Host permission scoped to YouTube only; matches stated function.
  • https://youtubetotranscript.com/* low Dev-owned backend domain; expected for AI feature calls.

Pillar Scores

Permissions2.60
Reputation6.50
Network2.00
Webstore4.50
Maintenance1.50
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-17 05:11
Listing SHA c829fec80220…
Force block — not fired
Score recovered no
Elapsed