Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WhatsApp AI Agents With CRM Integration | Eazybe

clgficggccelgifppbcaepjdkklfcefd
Risk Score
4.84
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 30,000
Rating 4.5
Last updated 2026-08-17 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer hey@eazybe.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — worst-case privacy posture.
  • <all_urls> host permission paired with scripting enables reading/modifying any page the user visits, including WhatsApp Web.
  • AI extension processing WhatsApp messages and CRM data — high-value data exfil surface if compromised.
  • Brand impersonation: extension claims WhatsApp association but developer domain eazybe.com is not confirmed owner.
  • No developer name listed and no verified-publisher badge despite broad data access and 30K installs.

Evidence

  • broad_host_access manifest <all_urls> host permission + scripting allows code injection on every site the user browses.
  • privacy_policy_fail api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy score (v3.5 rule D).
  • brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer eazybe.com is not confirmed owner.
  • ai_page_content store AI extension processing WhatsApp chats and CRM data across multiple SaaS platforms.
  • no_developer_name store developer_name is empty string; no verified publisher badge.
  • featured_by_google store is_featured_by_google=true provides partial reputation credit but does not offset privacy or brand-impersonation risks.
  • csp_absent_mv3 manifest csp_present=false on MV3; MV3 has strict default so no Network penalty, but no CSP still noted.
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — clean code surface.

Permissions Breakdown

  • storage low Standard local data persistence; low standalone risk.
  • tabs medium Can read URLs and titles of all open tabs.
  • alarms low Scheduling only; no data access.
  • scripting high Programmatic script injection into pages; elevated when paired with <all_urls>.
  • identity low OAuth token retrieval; scoped to user-approved flows.
  • identity.email medium Reads user's Google account email address without explicit OAuth scope approval UI.
  • <all_urls> (host_permission) high Grants script injection and network interception on every site; broadest possible reach.

Pillar Scores

Permissions6.50
Reputation5.50
Network3.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:18
Listing SHA 7f9c639528c3…
Force block — not fired
Score recovered no
Elapsed