Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Memos

cbhjebjfccgchgbmfbobjmebjjckgofe
Risk Score
4.26
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3,000
Rating 4.2
Last updated 2026-04-24 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer coorhook@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host permissions (http://*/* + https://*/*) with scripting allow code injection on every site visited.
  • Privacy policy is Google's generic policy — not scoped to this extension; scope_extension==false with data_collection+third_party_sharing==true yields max privacy score.
  • Developer uses free webmail (gmail) with no verified business identity, limiting accountability.
  • No CSP on MV3 extension with innerHTML DOM-XSS sink in view-image.js.
  • External JS hosts include tokinx.github.io — third-party GitHub Pages domain increases supply-chain risk.

Evidence

  • broad_host_permissions manifest host_permissions: http://*/* and https://*/* grant access to all sites combined with scripting.
  • generic_privacy_policy store Privacy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email coorhook@gmail.com; no verified publisher badge; no business domain.
  • dom_xss_sink crx js/view-image.js: innerHTML assigned from variable without sanitization; no CSP present.
  • external_js_hosts crx js_external_hosts includes tokinx.github.io — third-party GitHub Pages, potential supply-chain vector.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • low_install_count store Only 3,000 installs; limited blast radius but tail-attack-surface noted by anomaly check.
  • recently_updated store Last updated April 24, 2026 (2 months ago); maintenance risk is minimal.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles across all sites.
  • scripting high Allows programmatic script injection into pages; paired with broad host access.
  • windows low Window management; limited standalone risk.
  • storage low Local data storage only; no cross-origin risk.
  • activeTab low Scoped to user-activated tab; limited reach.
  • contextMenus low UI integration only; no data access.
  • http://*/* high Broad host access over all HTTP sites; enables scripting on any page.
  • https://*/* high Broad host access over all HTTPS sites; enables scripting on any page.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA 9af2ded09b4a…
Force block — not fired
Score recovered no
Elapsed 23.8s