Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

会译:一站式 AI 翻译 Agent|对照式DeepL翻译|DeepSeek划词翻译|免费

dgeiaiglmhdhajbpfbmajaajdlfdinpi
Risk Score
5.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 30,000
Rating 4.7
Last updated 2026-04-27 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer mopengcheng@nightingales.cn
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing (score: 10.0).
  • webRequest + scripting + <all_urls>: can read/modify all network traffic and inject code on every site visited.
  • Developer domain nightingales.cn does not resolve; no verified business identity behind the extension.
  • Uninstall URL hijack detected; extension registers a redirect on removal to an unknown target.
  • YouTube brand impersonation flagged (not a verified YouTube partner); AI translation extension processing full page content on all sites.

Evidence

  • privacy_policy_generic store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — scores +10.0.
  • developer_domain_no_resolve api nightingales.cn does not resolve; developer identity unverifiable despite verified_publisher=true.
  • uninstall_url_hijack manifest uninstall_url_hijack=true with null target recorded; +3.0 Webstore per rubric.
  • webRequest_all_urls manifest webRequest + <all_urls> + scripting: can observe and inject into all HTTP traffic.
  • brand_impersonation_youtube store brand_mention.is_impersonation=true for YouTube; developer not confirmed owner; +2.0 Reputation.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity disclosed.
  • js_external_hosts crx Extension contacts huiyiai.net and tinyurl.com; tinyurl is a link-shortener with opaque redirect destination.
  • csp_absent_mv3 manifest csp_present=false on MV3; MV3 provides strict default but no CSP amplifier applies per v2 rules.

Permissions Breakdown

  • storage low Standard local data persistence.
  • unlimitedStorage low Extended storage; low risk alone.
  • scripting high Executes arbitrary scripts in page context; paired with <all_urls> is high risk.
  • tts low Text-to-speech output; no data exfil risk.
  • contextMenus low Adds right-click menu items; minor surface.
  • webRequest high Can observe all network requests across all URLs.
  • sidePanel low Opens extension UI in side panel; low risk.
  • <all_urls> (host_permission) high Broad host access paired with scripting and webRequest multiplies risk significantly.

Pillar Scores

Permissions7.00
Reputation5.50
Network4.50
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:47
Listing SHA d1d6066d252a…
Force block — not fired
Score recovered no
Elapsed