Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ICPC Luxor CP-Training-Tracker

dalbkjmnafdmooclemgjckpfhkgibbja
Risk Score
3.27
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 27
Rating 5.0
Last updated 2026-08-04
Manifest version MV3
CSP present ❌ no
Developer icpcluxor@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Host permissions on 9+ AI platforms (ChatGPT, Claude, Gemini, Copilot, Grok, etc.) not justified by stated study-tracker function.
  • Privacy policy is 22-char stub with scope_extension=false and third_party_silence=true; effectively no disclosure.
  • Free-webmail developer (gmail.com) with no verified domain or publisher badge; low accountability.
  • Wildcard *.herokuapp.com host permission broader than the single pinned backend subdomain needed.
  • localhost:8080 host permission exposes local services on user machines.

Evidence

  • AI platform host permissions manifest 9 distinct AI chat platforms granted full host access; description only mentions Codeforces study tracking.
  • Privacy policy stub api Fetched policy is 22 chars long, scope_extension=false, data_collection=false, third_party_silence=true — inadequate.
  • Free-webmail developer email store icpcluxor@gmail.com; no verified publisher badge; domain_age_ct not queried due to free webmail.
  • Wildcard Heroku host manifest https://*.herokuapp.com/* grants access to any Heroku app subdomain beyond the named backend.
  • No CSP (MV3) manifest csp_present=false; MV3 has strict default so no v2 penalty applied, but noted.
  • No bad hosts / CVEs / obfuscation crx threat_intel.bad_host_hits=[], cve_findings_raw=[], obfuscation_score=0.0 — clean scan.
  • 27 installs, 0 operator siblings store Very small install base; operator_cluster.sibling_count=0; low blast radius.
  • Recently updated (0 months) store last_updated=August 4 2026; maintenance pillar = 0.

Permissions Breakdown

  • storage low Local state persistence; standard for tracking tools.
  • idle low Detects user idle state; appropriate for study-time tracker.
  • tabs medium Can enumerate open tabs and URLs; moderate read capability.
  • alarms low Scheduled callbacks; low direct risk.
  • notifications low Show desktop notifications; low risk in isolation.
  • windows low Enumerate browser windows; minor additional tab-context risk.
  • host:codeforces.com/* low Core stated function; narrow scope.
  • host:vjudge.net/* low Secondary CP platform; matches stated function.
  • host:localhost:8080/* medium Local backend access; could read other local services during dev.
  • host:*.herokuapp.com/* medium Wildcard Heroku subdomain; broader than a pinned backend URL.
  • host:*.railway.app/api/* low Path-scoped API wildcard; reasonable for backend deployment.
  • host:*.ondigitalocean.app/api/* low Path-scoped API wildcard; reasonable for backend deployment.
  • host:chatgpt.com/* medium Full access to ChatGPT sessions including chat content.
  • host:claude.ai/* medium Full access to Claude sessions including chat content.
  • host:gemini.google.com/* medium Full access to Gemini sessions.
  • host:aistudio.google.com/* medium Full access to AI Studio sessions.
  • host:poe.com/* medium Full access to Poe sessions.
  • host:chat.openai.com/* medium Redundant OpenAI host; full session access.
  • host:copilot.microsoft.com/* medium Full access to Copilot sessions.
  • host:copilot.cloud.microsoft/* medium Full access to Copilot enterprise sessions.
  • host:grok.com/* medium Full access to Grok sessions.
  • host:x.ai/* medium Full access to xAI sessions.

Pillar Scores

Permissions3.30
Reputation6.50
Network2.00
Webstore1.50
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 13:28
Listing SHA 8674b3312ebe…
Force block — not fired
Score recovered no
Elapsed