Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MaxFocus: Link Preview & AI Assistant

bnacincmbaknlbegecpioobkfgejlojp
Risk Score
2.69
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 10,000
Rating 4.6
Last updated 2026-08-20
Manifest version MV3
CSP present ❌ no
Developer hello@maxfoc.us
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (*://*/*) + content scripts on all URLs — extension reads/modifies every page visited.
  • AI extension processes page content; data sent to maxfoc.us backend per privacy policy.
  • Uninstall URL hijack flag set — may redirect user on removal even though target is null.
  • No developer name listed on store; reduces accountability signal.
  • JS external hosts include archive.is, youtube.com, google.com — broad reach for a productivity tool.

Evidence

  • verified_publisher + featured store Extension has verified publisher badge and is featured by Google; strong governance signal.
  • broad_host_access manifest host_permissions *://*/* and content_scripts <all_urls>; can access all sites.
  • uninstall_url_hijack crx uninstall_url_hijack=true but target=null; flag raised, actual redirect unknown.
  • privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
  • no_code_findings crx 0 code findings, obfuscation_score=0.0; 6 JS files scanned cleanly.
  • ai_extension_page_content store AI Assistant category; processes page content and sends to backend per privacy policy.
  • no_cve_findings crx No CVEs detected; no bundled vulnerable JS libraries.
  • js_external_hosts crx 8 external hosts including archive.is, youtube.com, github.com, google.com, localhost.

Permissions Breakdown

  • declarativeNetRequest medium Can block/modify network requests; less risky than webRequest but still impactful.
  • storage low Local data persistence; standard low-risk API.
  • contextMenus low Adds right-click menu items; minimal risk.
  • sidePanel low Opens a side panel UI; low risk surface.
  • *://*/* high Broad host permission; grants access to content on all sites including sensitive pages.
  • <all_urls> (content_scripts) high Content scripts injected on every page; can read/modify all page content.

Pillar Scores

Permissions5.10
Reputation2.00
Network2.00
Webstore5.50
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:35
Listing SHA cba45d46e67f…
Force block — not fired
Score recovered no
Elapsed