Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Keyboard Shortcuts for Websites

dgigbgdgmhhncfgaidcbmafkcmagkool
Risk Score
6.21
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 989
Rating 4.3
Last updated 2022-09-17 (45 months ago)
Manifest version MV3
CSP present ❌ no
Developer bhnmzm@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Extension last updated 45 months ago — zombie state with broad host access on all sites.
  • Privacy policy is generic Google account policy; not scoped to this extension, admits data collection and 3rd-party sharing.
  • Broad content-script host access (http://*/* + https://*/*) with no CSP — runs on every site.
  • Two innerHTML DOM-XSS sinks without CSP; no-CSP amplifies risk per v3 FIX B.
  • Gmail developer, small install base with high-perm anomaly flagged; no verified publisher.

Evidence

  • maintenance_stale store Last updated September 2022 — 45 months ago, > 36mo threshold, scores 10.0.
  • privacy_policy_generic store Policy URL is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 (v3.5 D).
  • broad_host_access manifest host_permissions http://*/* + https://*/* with content_scripts on same scope.
  • no_csp manifest content_security_policy is null; csp_present=false amplifies innerHTML XSS risk.
  • dom_xss_sink crx innerHTML assigned from variables in popup.js and content/shortcuts.js; no CSP protection.
  • gmail_developer store Developer email bhnmzm@gmail.com; free webmail, no business domain, no verified publisher.
  • install_perm_anomaly api 989 installs with high-tier host permissions — small_install_high_perm and tail_attack_surface both true.
  • is_featured_by_google store Featured badge present; applies -2.0 reputation discount but does not offset stale/privacy issues.

Permissions Breakdown

  • activeTab low Only active tab on user gesture; limited blast radius.
  • storage low Local storage for shortcut definitions; no exfil risk alone.
  • http://*/* high Broad host access — content scripts run on all HTTP sites.
  • https://*/* high Broad host access — content scripts run on all HTTPS sites.

Pillar Scores

Permissions5.00
Reputation6.50
Network2.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA a4212508f62e…
Force block — not fired
Score recovered no
Elapsed 25.1s