Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Claude Mythos — AI Chat

dabldgicbpmigbnfediggldlgdhcoljn
Risk Score
4.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 43
Rating 5.0
Last updated 2026-07-05 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer zhernokleevigor.dev@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'Claude' (Anthropic's trademark) without being affiliated — confirmed by brand_mention.
  • Privacy policy is Google's generic account policy; not scoped to this extension, admits data collection and 3rd-party sharing.
  • Free-webmail dev (gmail), no developer name, no verified publisher — unaccountable operator.
  • install_url_hijack: onInstalled redirects to mythos5.app/welcome, a third-party URL.
  • dom_sink_innerhtml_userctrl in sidepanel.js with no CSP present — DOM-XSS risk elevated.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; 'Claude' mentioned but dev is gmail user, confirmed_owner=false.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_developer_name store developer_name is empty string; free-webmail gmail dev; no verified publisher badge.
  • install_url_hijack manifest onInstalled opens https://mythos5.app/welcome — third-party redirect on install.
  • dom_xss_sink_no_csp crx innerHTML sink in sidepanel.js; csp_present=false elevates to +2.0 code quality risk.
  • ai_extension_page_content store AI chat extension processing user content via mythos5.app backend; +2.5 webstore AI signal.
  • no_cve_findings crx cve_findings_raw is empty; no known CVEs in bundled libraries.
  • low_install_count store Only 43 installs; extension is very new/obscure, limiting blast radius but also reducing trust signals.

Permissions Breakdown

  • sidePanel low Displays a side panel UI; no data access by itself.
  • storage low Local extension storage; limited blast radius.
  • https://mythos5.app/* low Scoped host permission to developer's own domain only.

Pillar Scores

Permissions0.60
Reputation8.50
Network0.00
Webstore6.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:21
Listing SHA 429cdf42f3c6…
Force block — not fired
Score recovered no
Elapsed