Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Discord Web Quest Completer

cgmommddnakeciakhimlbadjneifegng
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 20,000
Rating 4.1
Last updated 2026-01-30
Manifest version MV3
CSP present ❌ no
Developer gfxeye@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension name/function references Discord without being an official or verified Discord product.
  • Privacy policy is Google's own generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
  • Free-webmail developer (gmail.com) with no verified business identity or developer name.
  • declarativeNetRequestWithHostAccess + scripting on discord.com allows intercepting/modifying all Discord traffic.
  • No CSP declared (MV3 defaults apply, but youtube.com appears in external hosts fingerprint without clear justification).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[discord]; confirmed_owner=false; developer is gmail user.
  • free_webmail_developer manifest developer_email=gfxeye@gmail.com; no business website; no developer name listed.
  • privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • high_permissions manifest declarativeNetRequestWithHostAccess + scripting on https://discord.com/* enables full request interception and script injection.
  • js_external_host_youtube crx js_external_hosts=[www.youtube.com]; unclear why a Discord quest completer references YouTube JS.
  • no_cve_no_code_findings crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0; no malicious code detected.
  • recently_updated store last_updated=January 30, 2026; months_since_update=0; maintenance risk is minimal.
  • install_count store 20,000 installs; modest reach but non-trivial for a niche Discord automation tool.

Permissions Breakdown

  • declarativeNetRequestWithHostAccess high HIGH permission; can intercept/modify network requests to discord.com.
  • scripting high Can inject arbitrary scripts into pages; scoped to discord.com but still high-risk.
  • activeTab low Grants access only to the currently active tab on user gesture.
  • host:https://discord.com/* medium Scoped host access to Discord; enables scripting+network interception on the platform.

Pillar Scores

Permissions5.00
Reputation7.50
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:04
Listing SHA 1ceef9cd9f03…
Force block — not fired
Score recovered no
Elapsed 20.9s