Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Handy Screenshot - Full Page Screen Capture

dajlhodahakobmgdiglkajjgbchiiccf
Risk Score
4.03
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 40,000
Rating 4.8
Last updated 2026-06-12
Manifest version MV3
CSP present ✅ yes
Developer taining@ohhandy.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing.
  • Content scripts injected on <all_urls> including AI platforms (ChatGPT, Claude, Gemini) capturing potentially sensitive sessions.
  • Multiple new Function() constructor uses in content_script.js and core JS files; DOM innerHTML sink present.
  • Description promises recording but lacks tabCapture/desktopCapture — permission/promise mismatch.
  • No developer name listed; ohhandy.com domain resolves but CT log check failed — identity partially unverifiable.

Evidence

  • privacy_policy_generic store Privacy URL points to Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • host_permissions_all_urls manifest host_permissions includes <all_urls>; content_scripts also match AI platforms ChatGPT, Claude, Gemini.
  • code_function_constructor crx new Function() found in capture.js, settings.js, content_script.js, 295.js — dynamic code execution risk.
  • dom_innerhtml_sink crx innerHTML assignment from variable in 223.js; CSP sandbox present but limited to sandbox iframe.
  • description_promise_mismatch store Extension promises recording capability but lacks tabCapture/desktopCapture permissions.
  • verified_publisher_featured store Extension is verified publisher and featured by Google; ohhandy.com resolves, no throwaway signals.
  • js_external_hosts crx 12 external hosts including us-central1-ohhandytools.cloudfunctions.net; all appear dev-owned or known platforms.
  • no_developer_name store developer_name is empty string; only email taining@ohhandy.com provided.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction; appropriate for screenshot tool.
  • tabs medium Exposes tab URLs and metadata across all tabs.
  • storage low Local settings persistence; low standalone risk.
  • scripting medium Can inject scripts into pages; paired with <all_urls> raises capability.
  • notifications low UI notifications only; minimal abuse surface.
  • contextMenus low Adds right-click menu items; low risk.
  • identity low OAuth token access; no scopes declared, moderate concern.
  • <all_urls> (host_permission) high Content scripts on all URLs including ChatGPT, Claude, Gemini — broad reach.

Pillar Scores

Permissions4.50
Reputation2.00
Network3.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA 27818557157f…
Force block — not fired
Score recovered no
Elapsed 29.6s