Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Glasp Web Highlighter: PDF & Web Highlight

blillmbchncajnhkjfdnincfndboieik
Risk Score
4.83
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 500,000
Rating 4.5
Last updated 2026-05-20 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer hi@glasp.co
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed — no confirmed disclosure of data handling for 500K users.
  • brand_mention.is_impersonation=true (YouTube, ChatGPT, Claude, Gemini) without verified ownership.
  • Broad host_permissions *://* + content_scripts <all_urls> enables reading every page visited.
  • 7 external JS hosts (chatgpt.com, gemini.google.com, twitter.com, etc.) beyond own domain — wide network surface.
  • new Function() constructor in background bundle and PDF libs raises code-execution concern.

Evidence

  • broad_host_permissions manifest host_permissions: *://*/* combined with content_scripts on <all_urls> — runs on every page.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); privacy pillar scored at max.
  • brand_impersonation store brand_mention.is_impersonation=true; mentions YouTube, ChatGPT, Claude, Gemini; confirmed_owner=false.
  • external_hosts crx 8 external hosts including chatgpt.com, gemini.google.com, twitter.com, facebook.com, linkedin.com.
  • function_constructor_in_background crx new Function() found in background.bundle.js — dynamic code execution risk in privileged context.
  • featured_by_google store is_featured_by_google=true; applies -2.0 featured discount to reputation pillar.
  • no_developer_name store developer_name is empty string; only dev email hi@glasp.co present.
  • cve_clean crx cve_findings_raw is empty; jquery 3.7.1 is current; no CVE exposure.

Permissions Breakdown

  • activeTab low Temporary access to current tab on user action; low blast radius.
  • contextMenus low Adds right-click menu items; no data exfil risk alone.
  • tabs medium Can read tab URLs and titles across all tabs.
  • storage low Local/sync key-value store; no direct exfil path.
  • *://*/* (host_permissions) high Broad host access enables content script injection on every page visited.
  • content_scripts <all_urls> high Scripts run on every page; combined with broad host perm amplifies risk.

Pillar Scores

Permissions5.50
Reputation5.50
Network3.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA a4967a12c1af…
Force block — not fired
Score recovered no
Elapsed 25.3s