Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Custom Highlight

bmhaflbnleckffaacepbbbonfookcedm
Risk Score
5.05
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 9,000
Rating 4.0
Last updated 2025-02-28 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer andreas.o.tornkvist@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, but admits data collection and third-party sharing (+10.0 privacy).
  • Uninstall URL redirects to developer-controlled GitHub page; minor hijack signal.
  • Developer uses free webmail (gmail.com) with no verified business domain, raising accountability concerns.
  • <all_urls> host permission combined with 'scripting' allows code injection on every site the user visits.
  • Extension is 16 months stale (featured but not updated since Feb 2025); moderate abandonment risk.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • free_webmail_developer manifest Developer email is @gmail.com with no business domain; increases reputation risk.
  • host_permissions_all_urls manifest <all_urls> host permission + scripting enables injection on every site.
  • uninstall_url_hijack crx setUninstallURL targets andreto.github.io — developer-owned but still a 3rd-party redirect.
  • no_csp manifest content_security_policy is null; MV3 defaults apply but no explicit CSP hardening.
  • is_featured_by_google store Extension carries Google Featured badge, partially mitigating reputation risk.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; high-tier permission with sub-10K installs.
  • maintenance_stale store Last updated Feb 2025; 16 months since update → +6.0 maintenance pillar.

Permissions Breakdown

  • storage low Stores user highlight preferences locally; low impact.
  • scripting medium Allows programmatic script injection; elevated when paired with <all_urls>.
  • <all_urls> (host_permissions) high Content scripts run on every site; broad surface area for data access.

Pillar Scores

Permissions4.50
Reputation6.50
Network2.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA 51bda1dcf781…
Force block — not fired
Score recovered no
Elapsed 19.8s