Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screen Recorder for Google Chrome™

eclbecdgdoahkliaijlpkigldlkojjdn
Risk Score
4.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 600,000
Rating 4.2
Last updated 2026-07-10 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer alexeystore4@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: title uses Google™ trademark but developer is unverified gmail user with no dev name.
  • Privacy policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 per v3.5 rule D.
  • Install/uninstall URL hijack flags set; uninstall redirects to third-party URL (target unknown).
  • Description promises recording but lacks tabCapture/desktopCapture permissions — description mismatch detected.
  • Free-webmail dev (gmail) with no developer name; privacy policy domain (freebusinessapps.net) differs from dev email domain.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; title uses Google™ trademark; developer email is gmail, confirmed_owner=false.
  • privacy_policy_generic_with_data_sharing api Fetched policy: scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D +10.0.
  • install_uninstall_url_hijack crx install_url_hijack=true AND uninstall_url_hijack=true; targets not captured but pattern is monetization/redirect.
  • description_permission_mismatch store Promises recording but lacks tabCapture/desktopCapture; may be non-functional shell or misrepresented.
  • free_webmail_dev_no_name store developer_email=alexeystore4@gmail.com; developer_name empty; no verified business identity.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; partially offsets reputation risk.
  • no_csp manifest csp_present=false on MV3 extension; MV3 has strict default so no network penalty applied.
  • js_external_hosts crx js_external_hosts=[chrome.google.com, microsoftedge.microsoft.com]; both are known browser-vendor domains, low risk.

Permissions Breakdown

  • storage low Local key-value storage; standard for saving settings.
  • offscreen low Allows off-screen document creation; low standalone risk but used for capture pipelines.
  • unlimitedStorage low Unlimited local storage; reasonable for a recorder storing video files.

Pillar Scores

Permissions0.90
Reputation7.50
Network0.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

<fsssiedxa$'sssiedx 4.18 Medium review 2026-08-09
<fsssiedxa xx psssiedx 4.46 Medium review 2026-08-09
fsssiedxa<sssiedx 4.28 Medium review 2026-08-09
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.07 Medium review 2026-08-09
sssieddrubricxsx 4.17 Medium review 2026-08-09
v3.6 4.14 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA 645111a380dc…
Force block — not fired
Score recovered no
Elapsed 21.4s