Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Always Show Slack Workspace Switcher Sidebar

diebigeemhcipelnipggjihcmgjlacge
Risk Score
5.22
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 592
Rating 5.0
Last updated 2021-02-06 (64 months ago)
Manifest version MV3
CSP present ❌ no
Developer chrome-extension-publishers@monogon.tech
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Last updated Feb 2021 (64 months ago) — abandoned extension running on live Slack sessions.
  • Privacy policy is Google's generic account policy (scope_extension=false, admits data collection + 3rd-party sharing) — scores max privacy risk.
  • Brand impersonation flag: extension name references 'Slack' and developer is not a confirmed Slack owner.
  • No CSP (MV3 default enforced by Chrome, but adds to stale/abandoned signal).
  • Content script injects into app.slack.com — any future compromise/sale exposes all Slack session content.

Evidence

  • maintenance_stale store Last updated February 6, 2021 — 64 months ago; maintenance pillar = 10.0.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['slack']; confirmed_owner=false → +2.0 reputation.
  • content_script_slack manifest content_scripts_matches: *://app.slack.com/* — injects into Slack web app.
  • no_bad_hosts_no_cve crx bad_host_hits=[], cve_findings_raw=[], affiliate_hits=[], monetization_hits=[] — no active threat signals.
  • no_obfuscation_no_code_findings crx obfuscation_score=0.0, code_findings_raw=[] — clean code surface.
  • developer_domain_resolves api monogon.tech resolves=true, looks_throwaway=false; verified_publisher=false.
  • wayback_ownership_unchecked api wayback fetch error; ownership_changed=false but first_snapshot=null — cannot confirm history.

Permissions Breakdown

  • content_scripts: *://app.slack.com/* medium Injects scripts into Slack app; scoped to single domain, low blast radius.

Pillar Scores

Permissions1.00
Reputation6.00
Network2.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA 1c550be51893…
Force block — not fired
Score recovered no
Elapsed 20.0s