Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Save to Bookmark OS

cnmnalakipnobjijcnnnkbpeejjhhdkn
Risk Score
4.34
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 5,000
Rating 4.2
Last updated 2024-11-25 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer dave@bookmarkos.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection AND third-party sharing but is not scoped to this extension — D rule → +10.0 privacy.
  • Content scripts injected on ALL URLs (http://*/* + https://*/*) with no CSP, giving broad page-read capability.
  • Extension is 19 months stale (6-12mo band → +3.5 maintenance); v3.5 invariant 0c caps verified-publisher discount.
  • No developer display name increases identity accountability gap.
  • tail_attack_surface flagged: small install base with HIGH-tier host permission raises acquisition-risk concern.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D → +10.0 privacy.
  • broad_host_permissions manifest <all_urls> host permission + content_scripts on http://*/* and https://*/* — injected into every page visited.
  • no_csp crx content_security_policy is null; MV3 strict default applies, mitigating eval risk but no explicit declaration.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discount capped at -1.0 due to months_since_update=19 (>18).
  • maintenance_stale store Last updated November 2024; 19 months since update maps to 6-12mo band (+3.5) at scoring time.
  • no_developer_name store developer_name is empty string; identity accountability reduced, +1.0 reputation.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; low-install + HIGH-perm flag → +1.0 webstore.
  • clean_code_no_threats crx code_findings_raw empty, obfuscation_score=0.0, no bad/affiliate/monetization host hits, single US host.

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; needed for bookmark capture but enables browsing history inference.
  • <all_urls> (host_permission) high Content scripts injected into every site via http://*/* and https://*/* — broad reach.

Pillar Scores

Permissions4.50
Reputation2.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA 978ef695976b…
Force block — not fired
Score recovered no
Elapsed 21.9s