Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dora

dlbpmpcmedbgknmhanknkankmdnlokdp
Risk Score
4.88
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 86
Rating 5.0
Last updated 2026-08-25 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer tech.resources@trycoral.ai
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + scripting access to Epic EHR and OSUMC health portals exposes sensitive PHI to interception.
  • Privacy policy not scoped to this extension and does not disclose data collection — high privacy gap for a healthcare AI agent.
  • DOM-XSS sink (innerHTML with user-controlled variable) with no CSP present elevates XSS risk.
  • No developer name listed; very low install count (86) with high-impact healthcare permissions — tail attack surface.
  • No CSP on MV3 extension accessing healthcare portals; v2 network penalty applies.

Evidence

  • healthcare_host_access manifest Host permissions cover *.epic.com, *.epichosted.com, carelink.osumc.edu — major EHR/PHI environments.
  • webRequest_on_phi_hosts manifest webRequest declared alongside healthcare host permissions; can observe patient-lookup traffic.
  • no_csp manifest content_security_policy is null; no CSP defined for MV3 extension touching healthcare portals.
  • privacy_policy_not_scoped api privacy.trycoral.ai fetched; scope_extension=false, data_collection=false — generic, not extension-specific.
  • dom_xss_sink crx core/widget.js: body.innerHTML assigned from variable without sanitization; no CSP to mitigate.
  • no_developer_name store developer_name is empty string; reduces accountability for a healthcare-facing AI agent.
  • small_install_high_perm api 86 installs with HIGH-tier permissions (webRequest + healthcare host access) — install_perm_anomaly flagged.
  • domain_age_established api trycoral.ai first cert 2024-05-31, 431 certs, age 824 days — not a throwaway domain.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction only.
  • scripting medium Allows programmatic script injection into pages; moderate risk.
  • tabs medium Can read tab URLs and metadata across browser.
  • storage low Local extension storage, low direct risk.
  • webRequest high Can observe all network requests to permitted hosts including sensitive EHR portals.
  • host:https://app.trycoral.ai/* low Developer-controlled backend; expected for AI agent comms.
  • host:*://*.epic.com/* high Broad access to Epic EHR portal — sensitive patient data environment.
  • host:*://*.epichosted.com/* high Broad access to Epic-hosted EHR instances — sensitive patient data.
  • host:https://carelink.osumc.edu/* high Access to OSUMC patient portal — PHI exposure risk.
  • host:https://ihishswlnk.osumc.edu/* high Access to OSUMC health system link — PHI exposure risk.

Pillar Scores

Permissions6.50
Reputation6.00
Network4.00
Webstore3.00
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:17
Listing SHA 18afd3c8daba…
Force block — not fired
Score recovered no
Elapsed