Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SnapMaster – Screenshot & Editor

bllhjhfajpclmnlogplcfjjnlkmnlfmp
Risk Score
5.47
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, data collection and 3rd-party sharing admitted.
  • No developer identity: no name, no email, no verified publisher badge.
  • scripting + <all_urls> enables script injection into every site the user visits.
  • Description promises recording (tabCapture/desktopCapture) but permissions don't support it — permission/promise mismatch.
  • months_since_update unknown and no store metadata; lifecycle and maintenance cannot be assessed.

Evidence

  • host_permissions_all_urls manifest <all_urls> combined with scripting permission allows reading/injecting into every page visited.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • no_developer_identity store developer_name and developer_email both empty; no verified_publisher badge; no business identity.
  • description_promise_mismatch store Promises recording but lacks tabCapture/desktopCapture permissions.
  • no_csp manifest content_security_policy is null; MV3 strict default applies but no explicit policy declared.
  • maintenance_unknown store last_updated and months_since_update are null; maintenance score treated conservatively.
  • no_code_findings crx code_findings_raw is empty; obfuscation_score 0.0; 4 JS files scanned — no malicious signals detected.
  • no_cve_findings crx cve_findings_raw is empty; no known-vulnerable libraries bundled.

Permissions Breakdown

  • activeTab low Scoped to current tab on user action; limited reach.
  • storage low Local key-value storage; standard for saving editor state.
  • scripting medium Allows programmatic script injection into pages; medium risk on its own.
  • <all_urls> high Host permission grants access to content of every site visited.

Pillar Scores

Permissions5.50
Reputation7.50
Network2.00
Webstore4.00
Maintenance5.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:09
Listing SHA 38cc980bfce9…
Force block — not fired
Score recovered no
Elapsed