Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AuthoredUp – No. 1 LinkedIn ™ Content Tool

dkkmpkpjimkollpfgbbglcikcmgmdlhn
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 30,000
Rating 4.7
Last updated 2026-06-08
Manifest version MV3
CSP present ❌ no
Developer contact@authoredup.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; not patched to 1.12.1+.
  • Privacy policy fetched but scope_extension=false and admits data_collection+third_party_sharing — D rule triggers +10.0.
  • brand_mention.is_impersonation=true for LinkedIn without verified publisher — +2.0 reputation hit.
  • new Function() constructor found in guest and background scripts — code quality risk with no CSP present.
  • MV3 with no CSP: underscore CVE (DOM-manipulation lib) triggers ×1.5 CVE amplifier, pushing CVE pillar to 7.0.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (critical ACE); fixed_in 1.12.1 — library not upgraded.
  • high_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2026-27601 (high DoS via recursion); fixed_in 1.13.8.
  • no_csp manifest content_security_policy is null; no CSP defined — ×1.5 CVE amplifier applies.
  • privacy_policy_generic_admits_sharing store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
  • brand_impersonation store brand_mention.is_impersonation=true for LinkedIn; developer not verified_publisher nor featured by Google on impersonation check.
  • function_constructor crx new Function() constructor present in guest_script.js and background_script.js — dynamic code construction risk.
  • is_featured_by_google store Extension carries Google Featured badge — partial trust signal, applied -2.0 reputation discount.
  • host_permission_linkedin_only manifest Host access scoped to *.linkedin.com only; justified for LinkedIn content tool — no broad host access.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Local key-value store; no cross-site or exfil risk on its own.
  • *://*.linkedin.com/* medium Host permission scoped narrowly to linkedin.com; enables content-script injection on that domain.

Pillar Scores

Permissions2.00
Reputation5.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:07
Listing SHA eb8ce9dbb832…
Force block — not fired
Score recovered no
Elapsed 25.9s