Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web Client for game Cricket Batter Challenge

dcamdpfclondppklabgkfaofjccpioil
Risk Score
4.48
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 273
Rating 4.3
Last updated 2026-04-02 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer kiev3381917@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but admits third-party sharing without scoping to this extension — score +10.0.
  • Free-webmail Gmail developer with no verified business; numbered-alias pattern (kiev3381917) elevates rep risk.
  • function_constructor (new Function()) found in 3 JS files — dynamic code execution risk without CSP.
  • No content_security_policy (MV3 default is strict, but absence of explicit CSP with function_constructor is concerning).
  • Four distinct host_permissions including top.rodeo with no stated purpose; 3 countries of hosting increases geo-diversity surface.

Evidence

  • free_webmail_developer store Developer email kiev3381917@gmail.com — numbered alias, no verified business domain.
  • privacy_policy_third_party_sharing api Policy fetched but scope_extension=false, data_collection=false, third_party_sharing=true → +10.0 privacy.
  • function_constructor crx new Function() in background.js, content-sidebar.js, newtab-app.js — dynamic code execution.
  • no_csp manifest content_security_policy is null; MV3 default applies but explicit CSP absent alongside dynamic code patterns.
  • unrelated_host_permission manifest https://top.rodeo/* has no stated game/API purpose; raises suspicious outbound surface.
  • geo_diversity api JS hosts span CA, NL, US — 3 countries, below +1.5 threshold of 4.
  • low_install_count store Only 273 installs; limited blast radius but opaque developer identity.
  • manifest_name_localized manifest manifest_name and description use __MSG__ placeholders — description unverifiable from manifest directly.

Permissions Breakdown

  • storage low Local data persistence; low standalone risk.
  • sidePanel low UI surface for side panel; no data access.
  • https://www.googleapis.com/* medium Access to Google APIs; could be used to act on user's Google account data.
  • https://wheel.cloudapi.stream/* medium Developer-controlled CDN domain; opaque data flows possible.
  • https://mines.cloudapi.stream/* medium Second developer-controlled subdomain; widens outbound surface.
  • https://top.rodeo/* medium Unrelated third-party domain with no stated purpose; suspicious.

Pillar Scores

Permissions2.00
Reputation7.50
Network3.50
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:54
Listing SHA b7ed0d01a822…
Force block — not fired
Score recovered no
Elapsed