Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Merlin AI

camppjleccjaphfdbohjdohecfnoikec
Risk Score
5.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 900,000
Rating 4.8
Last updated 2026-06-08
Manifest version MV3
CSP present ❌ no
Developer support@getmerlin.in
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed (HTTPError); content of policy unknown — cannot confirm data handling practices.
  • webRequest + scripting + <all_urls> content scripts: can observe and modify all page content across every site.
  • AI extension processing page content on 900K installs — high-reach exfil surface if ever compromised.
  • No developer name listed; developer identity weakly established despite active domain.
  • Uninstall URL hijack flag set; post-removal tracking behavior present.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returned HTTPError; fetched=false. Policy content unverifiable — scored +10.0 privacy.
  • broad_host_permissions manifest host_permissions=['https://*/*'] + content_scripts <all_urls> + scripting + webRequest: full page access on all sites.
  • ai_extension_page_content store Detected as AI category with 900K installs and broad content script injection; +2.5 webstore AI signal.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension sets a post-uninstall URL. Raises webstore score.
  • no_developer_name store developer_name is empty string; identity relies solely on email support@getmerlin.in.
  • no_csp manifest content_security_policy=null (MV3 strict default applies); no explicit CSP declared.
  • clean_code_scan crx 403 JS files scanned; code_findings_raw empty, obfuscation_score=0.0, no CVEs detected.
  • featured_by_google store is_featured_by_google=true; reduces reputation concern. No bad host/affiliate/monetization hits.

Permissions Breakdown

  • sidePanel low UI surface only; no data access.
  • storage low Local data persistence; low standalone risk.
  • contextMenus low Adds right-click menu items; low risk.
  • tabs medium Can read tab URLs and titles; moderate privacy risk.
  • alarms low Scheduling only; no data access.
  • webNavigation medium Monitors navigation events across all pages; tracks user browsing.
  • webRequest high Can observe all network requests; significant surveillance capability.
  • scripting high Can inject JS into any page; combined with https://*/* is high risk.
  • https://*/* high Broad host access across all HTTPS sites; amplifies scripting/webRequest.
  • content_scripts <all_urls> high Content script injected into every page; reads/modifies page content universally.

Pillar Scores

Permissions7.50
Reputation5.00
Network3.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6 5.27 Medium review 2026-06-16
v3.4-rev 5.14 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA a8fab97a8b7a…
Force block — not fired
Score recovered no
Elapsed 25.6s