Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GPTSubs — X Premium Helper

chhbknablgnpbjokiakabbaekeohooec
Risk Score
4.32
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 34
Rating 5.0
Last updated 2026-08-24 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer lucky.eagle100@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + scripting on x.com/twitter.com enables full session token theft with no CSP guard.
  • Developer is free-webmail Gmail user with no verified identity or business website.
  • Privacy policy fetched but scope_extension=false and third_party_silence=true — effectively undisclosed.
  • DOM-XSS sink (innerHTML) in popup.js with no CSP; amplifies any injection vulnerability.
  • Small-install + high-perm anomaly (34 installs, cookies+scripting+host access) — tail attack surface.

Evidence

  • cookies+scripting+host_permissions on x.com manifest cookies + scripting + https://x.com/* + https://twitter.com/* allows full session read/write on social platform.
  • no CSP declared crx csp_present=false; MV3 has strict default but no explicit policy; DOM-XSS sink unmitigated.
  • free-webmail developer email store lucky.eagle100@gmail.com — numbered-alias pattern on Gmail, no verified business identity.
  • privacy policy inadequate api scope_extension=false, data_collection=false, third_party_silence=true — policy doesn't cover this extension.
  • dom_sink_innerhtml_userctrl in popup.js crx innerHTML assigned from variable without sanitization — DOM-XSS risk, no CSP mitigates.
  • install_perm_anomaly api Only 34 installs with HIGH-tier permissions (cookies + scripting + broad host) — tail attack surface.
  • privacy policy on .ru domain store gptsubs.ru — elevated-risk TLD for privacy policy hosting, no scope to this extension.
  • no verified publisher / featured badge store verified_publisher=false, is_featured_by_google=false — no accountability signals.

Permissions Breakdown

  • cookies high Can read/write cookies on x.com/twitter.com — sensitive auth token exposure risk.
  • clipboardWrite medium Can write to clipboard; limited scope but could inject malicious content.
  • activeTab low Scoped to user-activated tab; limited reach.
  • scripting medium Can inject scripts into x.com/twitter.com pages; combined with cookies raises risk.
  • https://x.com/* high Broad host access to X.com; combined with cookies allows full session capture.
  • https://twitter.com/* high Broad host access to Twitter.com; same session-capture risk as x.com.

Pillar Scores

Permissions4.50
Reputation6.50
Network2.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:20
Listing SHA 601e9706c0d9…
Force block — not fired
Score recovered no
Elapsed