Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Extensions shortcut

boalecjkpmcokhlmpomldpdeohipkkda
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 4,000
Rating 4.4
Last updated 2024-12-27 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer ihvarfner@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension at all (fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy).
  • Developer uses free Gmail address with no verified business presence, raising accountability concerns.
  • install_url_hijack flag is true, indicating onInstalled may open a third-party URL.
  • Extension is 18 months stale; at the boundary for maintenance risk.
  • Featured badge provides partial trust offset but developer identity remains unverified.

Evidence

  • privacy_policy_generic store Privacy policy is Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores +10.0 per v3.5 rule D.
  • install_url_hijack crx install_url_hijack=true; target=null. onInstalled likely opens a URL, scored +2.0 Webstore (install URL hijack).
  • free_webmail_developer store Developer email ihvarfner@gmail.com is free webmail; no business website. Reputation starts elevated.
  • is_featured_by_google store Extension carries Google Featured badge, applying -2.0 reputation discount.
  • maintenance_18mo store months_since_update=18; sits at 3-6 month boundary threshold giving +1.5 maintenance score.
  • no_cve_no_bad_hosts crx cve_findings_raw=[], bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no threat-intel hits.
  • minimal_permissions manifest Only 'commands' declared; no host_permissions, no content_scripts. Very low capability surface.
  • no_obfuscation_no_findings crx obfuscation_score=0.0, code_findings_raw=[], js_external_hosts=[]. Code quality is clean.

Permissions Breakdown

  • commands low Allows keyboard shortcut registration only; no data access or host access.

Pillar Scores

Permissions0.30
Reputation6.50
Network0.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA e39f412ede27…
Force block — not fired
Score recovered no
Elapsed 19.7s