Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

HARPA AI: Web Automation with ChatGPT, Claude, Gemini, Grok

eanggfilgoajaocelnaflolkadkeghjp
Risk Score
5.66
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 400,000
Rating 4.7
Last updated 2026-05-11 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@harpa.ai
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • browsingData+cookies+scripting+<all_urls>: can read, modify, exfil all site data and session credentials.
  • Privacy policy admits data_collection+third_party_sharing but scope_extension==false — no extension-specific disclosure.
  • brand_mention impersonation (ChatGPT, Claude, Gemini) without verified publisher status inflates reputation risk.
  • nj-engine.js executes new Function(userInput) — dynamic code eval surface in automation engine.
  • AI extension processing page content across all URLs creates broad passive data-collection surface.

Evidence

  • broad_host_permissions manifest host_permissions=[*://*/*] + content_scripts on *://*/* — all sites reachable.
  • high_capability_combo manifest browsingData + cookies + scripting + <all_urls>: can read/modify/exfiltrate full browsing state.
  • privacy_policy_unscoped api Policy fetched; data_collection+third_party_sharing=true but scope_extension=false → +10.0 privacy (v3.5-D).
  • brand_impersonation store is_impersonation=true (Claude, Gemini, ChatGPT); not verified_publisher, is_featured_by_google=true → +1.0.
  • dynamic_code_exec crx new Function(e)() in nj-engine.js executes user/page-supplied strings — code-quality risk.
  • ai_page_content store AI extension processing page content across all URLs; +2.5 webstore AI signal.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty.
  • featured_by_google store is_featured_by_google=true provides partial reputation mitigation (-2.0 featured badge).

Permissions Breakdown

  • alarms low Schedules background tasks; low standalone risk.
  • background low Persistent background page; expected for AI automation tool.
  • browsingData high Can delete cookies, cache, history — broad destructive capability.
  • cookies high Read/write all cookies across all sites via *://*/*.
  • declarativeNetRequest medium Can block/redirect network requests; moderate risk.
  • notifications low Display notifications; minimal risk.
  • tabs medium Access URL, title, tab state across all tabs.
  • storage low Local/sync storage; low risk.
  • offscreen low Offscreen document API; contained risk.
  • scripting high Inject arbitrary scripts into *://*/* pages — critical capability.
  • contextMenus low Adds right-click menu items; minimal risk.
  • sidePanel low UI side panel; minimal risk.
  • *://*/* high Broad host access covering all URLs; amplifies every other permission.

Pillar Scores

Permissions7.50
Reputation5.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Scoring History

v3.6 5.66 Medium review 2026-06-16
v3.4-rev 6.04 High review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA 17caa1f43894…
Force block — not fired
Score recovered no
Elapsed 33.6s