Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sider: Chat with all AI: GPT-5, Claude, DeepSeek, Gemini, Grok

difoiogjjojoaoomphldepapgpbgkhkb
Risk Score
4.50
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 5,000,000
Rating 4.9
Last updated 2026-09-03
Manifest version MV3
CSP present ✅ yes
Developer care@sider.ai
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed — no verifiable data-handling disclosure for 5M-user AI extension with <all_urls> access.
  • cookies + <all_urls> + scripting combo: can read session cookies and inject JS on every site the user visits.
  • 20 dom_sink_innerhtml_userctrl findings across content scripts expose DOM-XSS attack surface on all visited pages.
  • brand_mention.is_impersonation=true: extension name drops Claude, Gemini, DeepSeek branding without confirmed ownership.
  • Uninstall URL hijack detected and no developer name listed, reducing accountability signals.

Evidence

  • host_permissions_broad manifest <all_urls> + cookies + scripting = full page read/write and cross-site cookie access on every URL.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (HTTPError); policy content unverifiable → pillar scores 10.0.
  • brand_impersonation store brand_mention.is_impersonation=true; brands: deepseek, claude, gemini; confirmed_owner=false; not verified publisher.
  • uninstall_url_hijack crx uninstall_url_hijack=true; redirects to unspecified 3rd-party URL on uninstall.
  • dom_xss_sinks_widespread crx 16 files contain dom_sink_innerhtml_userctrl; CSP present but sandbox allows external GA/Facebook/Twitter JS.
  • function_constructor crx new Function() found in 4 api.js files under js/v2/ — dynamic code execution risk.
  • csp_sandbox_external_scripts manifest Sandbox CSP allows ssl.google-analytics.com, connect.facebook.net, platform.twitter.com — remote script sources.
  • no_developer_name store developer_name is empty string; reduces accountability; email care@sider.ai on resolving domain sider.ai.

Permissions Breakdown

  • storage low Stores extension state locally.
  • cookies high Can read/write cookies across all sites given <all_urls> host access.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • scripting high Programmatic script injection on any page with <all_urls>.
  • activeTab medium Grants temporary access to current tab on user action.
  • unlimitedStorage low No data-exfil capability, only local storage quota.
  • tabs medium Reads URL/title of all open tabs.
  • sidePanel low UI surface only.
  • offscreen low Background DOM processing; limited standalone risk.
  • alarms low Periodic wake-ups; no direct data access.
  • declarativeNetRequest medium Can modify/block network requests declaratively.
  • <all_urls> (host) high Broad host access amplifies cookies+scripting to every site visited.
  • https://*.openai.com/ (host) high Explicit access to OpenAI sessions and API traffic.

Pillar Scores

Permissions7.80
Reputation5.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Scoring History

sssiedn97909494dp727562726963xsx 4.75 Medium review 2026-09-07
sssiedn93648d72dp727562726963xsx 6.25 High review 2026-09-06
xx pfsssiedxn<sssiedx 6.21 High review 2026-08-19
&#x27;fsssiedxn$"sssiedx 6.26 High block 2026-08-19
<fsssiedxg$"sssiedx 6.47 High review 2026-08-19
<fsssiedxa&#x22;sssiedx 6.11 High review 2026-08-10
<fsssiedxi'sssiedx 6.34 High review 2026-08-10
<fsssiedxi$"sssiedx 6.22 High review 2026-08-10
<fsssiedxa$'sssiedx 6.44 High review 2026-08-10
<fsssiedxa'sssiedx 6.21 High review 2026-08-10
<fsssiedxa sssiedx 4.63 Medium review 2026-08-10
fsssiedxa<sssiedx 6.31 High review 2026-08-10
<fsssiedxf$"sssiedx 6.23 High review 2026-08-07
%22fsssiedxg$"sssiedx 6.33 High review 2026-08-07
fsssiedxg<sssiedx 6.08 High review 2026-08-07
<fsssiedxi"sssiedx 4.63 Medium review 2026-08-07
<fsssiedxa xx psssiedx 6.56 High review 2026-08-07
<fsssiedxa$"sssiedx 6.38 High review 2026-08-07
dfb__${98991*97996}__::.x 6.27 High review 2026-08-05
v3.6'"()&%<zzz><ScRiPt >OaYk(9139)</ScRiPt> 4.68 Medium review 2026-08-05
<fsssiedxa"sssiedx 6.51 High block 2026-08-01
fsssiedx<sssiedx 6.63 High review 2026-08-01
v3.69267"();}]9976 6.27 High review 2026-07-29
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%79%6C%4A%51%28%39%36%38%30%34%29%22 6.58 High review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 6.42 High review 2026-07-29
<th:t="${dfb}#foreach 6.78 High review 2026-07-29
dfb{{98991*97996}}xca 4.73 Medium review 2026-07-29
v3.69472288< 6.27 High review 2026-07-29
v3.6&n928085=v994387 6.31 High review 2026-07-29
fsssiedxa sssiedx 6.02 High review 2026-07-28
fsssiedxa&#x27;sssiedx 6.07 High review 2026-07-28
fsssiedxa'sssiedx 6.05 High review 2026-07-28
sssieddrubricxsx 6.24 High block 2026-07-28
v3.6 4.50 Medium review 2026-06-16
v3.4-rev 4.21 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA ab66f187ca10…
Force block — not fired
Score recovered no
Elapsed 34.4s