Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AiSenseUs - AI Meeting Notes, Transcription & Summaries Assistant

cbojomnehgiadpclibfpidkipekmeldd
Risk Score
4.64
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 11
Rating 5.0
Last updated 2025-11-03 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer vdsoftware@outlook.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (outlook.com) with no developer name — unverifiable identity for a meeting-audio AI tool.
  • Brand impersonation: extension claims Google Meet, Zoom, Teams support but developer is not an affiliate/owner.
  • Privacy policy not scoped to this extension and third-party silence flag active — data handling undisclosed.
  • AI extension processes sensitive meeting audio/transcriptions via api.aisenseus.net with no CSP guardrails.
  • No CSP on MV3 extension contacting 8 external JS hosts including script.google.com and stackoverflow.com.

Evidence

  • free_webmail_no_dev_name store Developer email vdsoftware@outlook.com; developer_name is empty — no verified identity.
  • brand_impersonation store brand_mention: Google, Zoom, Teams mentioned; confirmed_owner=false, is_impersonation=true.
  • privacy_policy_not_scoped api Policy fetched but scope_extension=false, data_collection=true, third_party_silence=true → score +9+1.
  • no_csp crx content_security_policy is null; extension contacts 8 external hosts with no script restriction.
  • external_hosts_diverse crx js_external_hosts includes script.google.com, stackoverflow.com alongside aisenseus.net endpoints.
  • install_url_hijack crx install_url_hijack=true targeting meetings.html on install — opens page on extension install.
  • ai_meeting_content store AI extension processes meeting audio/transcripts; data sent to api.aisenseus.net (NL-hosted).
  • low_install_count store Only 11 installs; no community validation for a tool with access to sensitive meeting content.

Permissions Breakdown

  • storage low Local state persistence; standard for productivity extensions.
  • downloads medium Can write files to disk; could export meeting recordings or data.
  • scripting medium Dynamic script injection into pages; scoped only to meet.google.com host.
  • https://meet.google.com/* medium Host access to Google Meet; narrows scope but grants full DOM/audio access on meetings.

Pillar Scores

Permissions2.30
Reputation7.50
Network3.50
Webstore5.00
Maintenance3.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:34
Listing SHA 01620a680a8a…
Force block — not fired
Score recovered no
Elapsed