Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

UI Inspector - Visual CSS Editor

dadpnbadaicglhbgoboopllcbemfipoo
Risk Score
3.76
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 4,000
Rating 4.0
Last updated 2026-04-05 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer violetsmyster@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returned HTTP error (fetch_error) — cannot confirm adequacy; treated as missing.
  • Developer uses free webmail (gmail) with no developer name, reducing accountability.
  • install_url_hijack is true — onInstalled opens a URL, possibly to Gumroad for upsell.
  • Extension contacts external hosts api.gumroad.com and mrviolets.gumroad.com (monetization/licensing check).
  • No content security policy declared (MV3 default applies but no explicit hardening).

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false due to HTTPError; scored as +10.0 privacy pillar.
  • install_url_hijack crx install_url_hijack=true; target null but Gumroad fingerprint suggests monetization redirect on install.
  • gumroad_external_hosts crx js_external_hosts: api.gumroad.com, mrviolets.gumroad.com — licensing/payment calls, not ad-tech.
  • free_webmail_no_dev_name store developer_email=violetsmyster@gmail.com, developer_name empty; reduces accountability.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; applied -3.0/-2.0 reputation discounts.
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty; code quality benign.
  • recently_updated store months_since_update=2; maintenance pillar 0.0.
  • no_broad_host_permissions manifest host_permissions=[], content_scripts_matches=[]; narrow capability scope.

Permissions Breakdown

  • scripting medium Can inject JS/CSS into active tab; scoped by activeTab so limited blast radius.
  • activeTab low Access only to user-invoked tab; transient, low persistent risk.
  • storage low Local data persistence only; no exfil vector on its own.
  • declarativeContent low Page-state matching to show browser action; no content read.
  • sidePanel low UI surface only; no data access.
  • commands low Keyboard shortcut registration; no data access.
  • contextMenus low Adds menu items; no data access.
  • fontSettings low Reads/sets browser font settings; limited scope.

Pillar Scores

Permissions2.30
Reputation5.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA d89aa0f386d1…
Force block — not fired
Score recovered no
Elapsed 22.3s