Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Annotate PRO

clpoilnjjdbfjinifhmcfddhjgneajle
Risk Score
4.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 5,000
Rating 4.9
Last updated 2026-04-21 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer info@11trees.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: scored as worst-case generic policy (+10.0).
  • Brand impersonation flagged (Google, Microsoft, Teams mentioned; confirmed_owner==false); developer name absent from store listing.
  • 4 innerHTML DOM-XSS sinks in content scripts running on <all_urls>, amplified by CVE-affected jQuery 3.4.1 (CVE-2020-11022/11023).
  • install_url_hijack and uninstall_url_hijack both true; uninstall redirect to unknown 3rd-party target.
  • 12 distinct external JS hosts including Firebase, Bootstrap CDN, Chart.js, Quill — broad network surface for annotation tool.

Evidence

  • privacy_policy_generic_with_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
  • brand_impersonation store brand_mention.is_impersonation=true; brands: google, teams, microsoft; confirmed_owner=false; not verified publisher.
  • dom_xss_sinks_with_cve_jquery crx 4 innerHTML sinks in content scripts + jQuery 3.4.1 with CVE-2020-11022/11023 unfixed; DOM-XSS risk on all pages.
  • install_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; uninstall target null (obfuscated 3rd-party redirect).
  • broad_host_plus_scripting manifest host_permissions <all_urls> + scripting + content_scripts on <all_urls>; can read/modify every page visited.
  • 12_external_js_hosts crx js_external_hosts has 12 distinct domains incl. Firebase RT DB, Bootstrap CDN, Quill, Chart.js, datatables.net.
  • developer_name_missing store developer_name is empty string; reduces accountability; reputation base elevated.
  • is_featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount (featured badge) but does not override privacy/impersonation risk.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • activeTab low Scoped to user-initiated interactions only.
  • clipboardWrite medium Can write to clipboard; moderate risk for data injection.
  • clipboardRead medium Can read clipboard content; risk of sensitive data exfil.
  • contextMenus low UI integration only, low standalone risk.
  • offscreen low Allows offscreen document; moderate capability but low alone.
  • tabs medium Can read tab URLs and titles across all tabs.
  • scripting high Can inject scripts into pages; combined with <all_urls> is high risk.
  • storage low Local data persistence, low direct risk.
  • webNavigation medium Can observe navigation events across all URLs.
  • <all_urls> (host_permissions) high Broad host access paired with scripting and content_scripts on all URLs.

Pillar Scores

Permissions6.50
Reputation6.00
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA e6c2e1fef478…
Force block — not fired
Score recovered no
Elapsed 35.5s