Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

cfkkdamfechdeemgmgbbilmjhkcjmdhp

cfkkdamfechdeemgmgbbilmjhkcjmdhp
Risk Score
4.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijack both flagged with null targets — classic traffic-monetization shell pattern.
  • Privacy policy is generic Google account policy, not scoped to this extension; scope_extension=false with data_collection+third_party_sharing=true → max privacy risk.
  • Extension title and description are unresolved i18n keys (__MSG_*) — no verifiable identity or function.
  • No developer name, email, or verifiable domain; js_external_hosts points to gameograf.com indicating possible game-portal shell.
  • Extension is essentially empty (no permissions, no host access, no content scripts) yet contacts external host gameograf.com.

Evidence

  • install_url_hijack + uninstall_url_hijack both true manifest Both onInstalled and uninstall hooks fire to external URLs (targets null/not extractable) — monetization shell indicator.
  • js_external_hosts: gameograf.com crx External JS host gameograf.com detected; game-portal shell pattern association.
  • Generic Google privacy policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true — generic/unscoped.
  • No developer identity store developer_name, developer_email, and developer_domain all empty/null; no verified publisher badge.
  • Empty manifest with external host manifest Zero permissions, host_permissions, and content_scripts_matches declared; 2 JS files still reference gameograf.com.
  • Unresolved i18n manifest name/description manifest manifest_name=__MSG_appName__, manifest_description=__MSG_appDesc__; true function unverifiable.
  • No CSP declared manifest content_security_policy is null; MV3 has default CSP but explicit absence noted alongside external host.
  • Game-portal shell fingerprint crx operator_cluster fingerprint contains gameograf.com; combined with URL hijacks matches game-portal monetization shell.

Pillar Scores

Permissions0.00
Reputation8.50
Network0.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 12:21
Listing SHA c53aae183306…
Force block — not fired
Score recovered no
Elapsed