Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bulk Slack Message Removal

dahaofhkbloejmcijfknenbdgohmmeen
Risk Score
6.18
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 1,000
Rating 4.6
Last updated 2025-08-24 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer lihster.developer@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies+webRequest on *.slack.com — full session token interception possible; proxied through dev-controlled AWS Lambda.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic company policy).
  • Brand impersonation: Slack brand used by unverified free-webmail developer with no developer name listed.
  • Slack proxy Lambda endpoint routes extension traffic through opaque server infra — exfiltration surface.
  • No CSP + innerHTML sinks in two files — DOM-XSS risk if Slack content injected into extension UI.

Evidence

  • cookies+webRequest+*.slack.com host manifest HIGH permissions cookies and webRequest paired with *.slack.com; ×1.2 multiplier applied.
  • slack_proxy Lambda endpoint manifest https://gkzwmpfdz5.execute-api.us-east-2.amazonaws.com/default/slack_proxy is a dev-controlled relay.
  • brand impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, developer_email=gmail.com, no dev name.
  • privacy policy: data_collection+third_party_sharing, scope_extension=false api v3.5D: fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • no CSP + innerHTML sinks crx csp_present=false, two dom_sink_innerhtml_userctrl findings; FIX B applies → +2.0 code quality.
  • verified_publisher=true but free-webmail dev email store Verified publisher badge present but email is gmail.com; 0c cap may apply if monetization detected.
  • js_external_hosts includes fb.me and reactjs.org crx Extension references fb.me and reactjs.org as external hosts; 2 countries (IN, US).
  • monetization shape: Gumroad + LemonSqueezy endpoints manifest Host perms to api.gumroad.com and lemonsqueezy Lambda confirm paid-license model.

Permissions Breakdown

  • storage low Stores extension settings locally; limited blast radius.
  • webRequest high Can observe all HTTP requests on permitted hosts including Slack auth tokens.
  • cookies high Can read/write cookies; paired with Slack host access risks session token theft.
  • *://*.slack.com/* high Broad host access to entire Slack workspace; enables interception of all messages and tokens.
  • https://wfttznwxih.execute-api.us-east-2.amazonaws.com/prod/lemonsqueezy medium Opaque Lambda endpoint for payment processing; unverifiable data handling.
  • https://gkzwmpfdz5.execute-api.us-east-2.amazonaws.com/default/slack_proxy high Slack proxy Lambda — could relay Slack API calls/tokens through dev-controlled infra.
  • https://api.gumroad.com/* medium License-check endpoint; low direct risk but confirms monetized extension model.

Pillar Scores

Permissions7.20
Reputation7.50
Network5.50
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA 55af62c26c53…
Force block — not fired
Score recovered no
Elapsed 30.6s