Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AutoHD for Twitch™

didbenpmfaidkhohcliedfmgbepkakam
Risk Score
6.24
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 1,000
Rating 3.7
Last updated 2025-02-05 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer karsten@autohd.org
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Twitch brand impersonation by unverified developer 'karsten' with no confirmed ownership of the mark.
  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • declarativeNetRequestWithHostAccess + https://*/*: can intercept and modify requests on all HTTPS sites.
  • Content scripts injected on <all_urls> with no CSP; DOM-XSS sink (innerHTML) present in popup JS.
  • Extension last updated 18 months ago; at boundary of stale classification with high-capability permissions.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'twitch'; developer domain autohd.org not confirmed owner.
  • generic_privacy_policy store Privacy policy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • broad_host_access manifest host_permissions=['https://*/*'] + content_scripts on <all_urls> + declarativeNetRequestWithHostAccess.
  • dom_xss_sink crx code_findings_raw: dom_sink_innerhtml_userctrl in popup.100f6462.js; no CSP present (MV3 default only).
  • stale_extension store months_since_update=18; at 18mo boundary with HIGH-tier permissions active.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 1,000 installs with HIGH-tier permissions increases supply-chain risk.
  • external_js_host crx js_external_hosts=['reactjs.org']; external JS reference present though no bad-host hits detected.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; single-name dev 'karsten' with no org backing.

Permissions Breakdown

  • storage low Stores user preferences locally; minimal risk.
  • tabs medium Can read tab URLs and titles; moderate privacy surface.
  • declarativeNetRequestWithHostAccess high Can intercept/modify network requests across all HTTPS sites.
  • https://*/* high Broad host access pairs with declarativeNetRequestWithHostAccess — high capability.
  • content_scripts:<all_urls> high Injects scripts into every page; large attack surface for DOM manipulation.

Pillar Scores

Permissions7.50
Reputation7.00
Network2.50
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:06
Listing SHA 5b2853cb1280…
Force block — not fired
Score recovered no
Elapsed