Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ClipKeeper - For Use with GameChanger

beelllgidjaklbnacknjkghfibfpjhac
Risk Score
3.04
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category MediaDownloader
Installs 774
Rating 5.0
Last updated 2026-08-17
Manifest version MV3
CSP present ✅ yes
Developer cjessup87@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail developer with no registered business name increases accountability gap.
  • Uninstall and install URL hijack flags set (targets null, but hooks are present).
  • innerHTML sink in content.js is a DOM-XSS risk on gc.com pages.
  • new Function() in bundled jszip.min.js; CSP present mitigates but library-level risk remains.
  • Privacy policy discloses third-party sharing but lacks data-retention details.

Evidence

  • developer_email_free_webmail store Developer email cjessup87@gmail.com; no verified business name or domain.
  • verified_publisher store Extension has verified_publisher=true, partially offsetting reputation concern.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; target is null so no confirmed 3rd-party redirect.
  • install_url_hijack crx onInstalled URL hook present; target is null so no confirmed 3rd-party redirect.
  • dom_sink_innerhtml_userctrl crx innerHTML used in content.js; CSP is present (script-src 'self') limiting exploit reach.
  • function_constructor_in_jszip crx new Function() in libs/jszip.min.js; standard jszip pattern, CSP 'self' mitigates remote loading.
  • privacy_policy_no_retention api Policy scoped to extension, discloses 3rd-party sharing, but retention period not specified.
  • js_external_hosts_raw_github crx raw.github.com and stuk.github.io in js_external_hosts; risk of remote script dependency.

Permissions Breakdown

  • storage low Standard local state storage; low risk.
  • downloads medium Can trigger file downloads to user disk; appropriate for media-backup function.
  • offscreen low Needed for background media processing; no direct data-access risk.
  • https://web.gc.com/* low Scoped to GameChanger web app only; matches stated purpose.
  • https://vod-archive.gc.com/* low Scoped to GameChanger VOD subdomain; matches video-backup function.
  • https://usvlgqtbvsnuiefvpoda.supabase.co/* medium Backend Supabase instance; external data endpoint warrants scrutiny but fits SaaS model.

Pillar Scores

Permissions2.30
Reputation5.50
Network1.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality3.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:26
Listing SHA d6974e7c813c…
Force block — not fired
Score recovered no
Elapsed