Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Voila – AI Assistant, Copilot and AI Writer

cakobppopkpmmglabcdcklncbckjpkcl
Risk Score
5.09
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 80,000
Rating 4.7
Last updated
Manifest version MV3
CSP present ✅ yes
Developer hello@getvoila.ai
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is on speeddial2.com (unrelated domain), admits data collection and 3rd-party sharing without scoping to this extension.
  • Content scripts injected on <all_urls> — reads/modifies every page the user visits including mail and banking.
  • Brand impersonation: 'Copilot' mentioned in title without verified ownership; no developer name disclosed.
  • multiple new Function() constructors across 6 JS files plus dynamic script injection; elevated code risk surface.
  • AI extension with broad page access posts content to external hosts including CloudFront CDN and frontapp.com.

Evidence

  • privacy_policy_mismatch store Policy URL is speeddial2.com, not getvoila.ai; scope_extension=false, data_collection=true, third_party_sharing=true.
  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls>, http://*/* and https://*/* — full-page injection on every site.
  • brand_impersonation store brand_mention.is_impersonation=true for 'copilot'; confirmed_owner=false; no developer name in listing.
  • code_function_constructor crx new Function() constructor in background.js, gmail-extension.js, outlook-extension.js, gmail-injector.js, paddle.js.
  • dynamic_script_injection crx script_src_dynamic in d-contentscript.js; uses chrome.runtime.getURL so internal-only, but still dynamic.
  • external_hosts crx JS contacts app.frontapp.com, d2u6w5ruxmbk4z.cloudfront.net, github.com, www.getvoila.ai (3 non-dev domains).
  • is_featured_by_google store Extension carries Google Featured badge, providing partial reputation signal.
  • ai_page_content store AI writing assistant with <all_urls> content scripts — page content likely sent to AI backend.

Permissions Breakdown

  • storage low Standard local data storage; low risk.
  • unlimitedStorage low Allows large local storage; minor risk of disk abuse.
  • contextMenus low Adds right-click menu items; low risk.
  • tabs medium Can read tab URLs and titles; moderate privacy risk.
  • alarms low Schedules background tasks; low risk.
  • content_scripts:<all_urls> high Injects JS into every page; broad read/write access to page content.

Pillar Scores

Permissions3.50
Reputation5.50
Network3.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Scoring History

sssiedn91b96562dp727562726963xsx 5.17 Medium review 2026-09-09
v3.6 5.09 Medium review 2026-06-18

Bookkeeping

Rubric v3.6
Scored at 2026-06-18 07:37
Listing SHA 994694444750…
Force block — not fired
Score recovered no
Elapsed