Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CHATBOTY App

dkgcodmnjmlmgmdlbekkcjjjidkflnal
Risk Score
6.73
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 18
Rating
Last updated 2026-09-04
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Operator cluster of 23 sibling extensions under same dev email — mass deployment / farm pattern.
  • Privacy policy is Google's own policy, not scoped to this extension; admits data collection and 3rd-party sharing.
  • Uninstall and install URL hijacks detected; install redirects to WhatsApp Web on behalf of user.
  • WhatsApp brand impersonation by unverified developer on extensao.store domain.
  • function_constructor (new Function) used in 4 files with no CSP — dynamic code execution risk on WhatsApp DOM.

Evidence

  • operator_cluster_sibling_count_23 api 23 sibling extensions share same dev email, install URL, and CSP host set — strong farm fingerprint.
  • uninstall_url_hijack_and_install_url_hijack crx Both uninstall and install URL hijacks present; install redirects to https://web.whatsapp.com.
  • brand_impersonation_whatsapp store Extension mentions WhatsApp brand; developer domain extensao.store is not a confirmed WhatsApp owner.
  • privacy_policy_generic_google store Policy URL is Google Account privacy page — not scoped to this extension; data_collection=true, third_party_sharing=true.
  • function_constructor_no_csp crx 4 new Function() calls across multiple JS files; csp_present=false amplifies DOM code-execution risk.
  • js_external_hosts_10_domains crx 10 distinct external wascript.com.br / watools.com.br endpoints contacted — broad backend surface.
  • dom_sink_innerhtml_no_csp crx innerHTML user-controlled sink present with csp_present=false — DOM-XSS elevated risk.
  • host_perm_whatsapp_web manifest Full content-script access to https://web.whatsapp.com/* — can read all WhatsApp Web messages.

Permissions Breakdown

  • unlimitedStorage low Allows unlimited local data storage; low risk in isolation.
  • storage low Standard key-value storage; low risk.
  • alarms low Scheduling alarms; low risk.
  • tabs medium Can read tab URLs and titles; moderate privacy exposure.
  • host_permissions: https://web.whatsapp.com/* medium Full access to WhatsApp Web DOM; can read messages and user data.

Pillar Scores

Permissions2.30
Reputation7.00
Network3.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 05:06
Listing SHA 927286249308…
Force block — not fired
Score recovered no
Elapsed