Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DeepSeek to PDF - Export DeepSeek Chats to PDF, Markdown, JSON

ecmcbpjdknbbcfbohfcjjilgkgclgdbc
Risk Score
4.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 307
Rating 4.7
Last updated 2026-08-29 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer neocrtxai@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • DeepSeek brand impersonation by unverified gmail dev with no developer name; potential for phishing or supply-chain abuse.
  • Developer-controlled backend (GCP Cloud Run) receives DeepSeek chat content — opaque data pipeline with no scoped privacy policy.
  • Privacy policy fetched but scope_extension==false and third_party_silence==true; no meaningful data handling disclosures.
  • 8 innerHTML DOM-XSS sinks across content scripts ingesting AI chat HTML; risk of stored-XSS from malicious chat content.
  • CSP connect-src is broadly open ('connect-src * data: blob: filesystem:') allowing exfiltration to arbitrary endpoints.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'deepseek'; developer domain is gmail.com, confirmed_owner=false.
  • gmail_dev_no_name store developer_email=neocrtxai@gmail.com, developer_name empty; free-webmail dev with no verified business.
  • install_url_hijack manifest install_url_hijack=true; extension opens URL on install — minor but noteworthy behaviour.
  • csp_connect_broad manifest connect-src * data: blob: filesystem: — allows outbound connections to any host from extension pages.
  • developer_backend_host crx js_external_hosts includes GCP Cloud Run backend receiving chat data; host_permissions also grant it access.
  • privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=false, retention=false, third_party_silence=true.
  • multiple_innerHTML_sinks crx 8 dom_sink_innerhtml_userctrl findings across content scripts processing AI-generated HTML.
  • multi_search_engine_contact crx threat_intel shows 3 search engines (google, yandex.com, yandex.ru) contacted; extension is not NewTab category.

Permissions Breakdown

  • storage low Local state persistence; minimal risk.
  • downloads medium Can save files to disk; appropriate for PDF/export use-case.
  • downloads.open medium Can auto-open downloaded files; slight UX-abuse risk.
  • identity medium OAuth token access; used for cloud storage integrations (Dropbox, Notion, Yandex).
  • activeTab low Scoped to user-invoked tab; low blast radius.
  • host:*.amazonaws.com medium Broad AWS access; could reach developer backend or S3 uploads.
  • host:*.deepseek.com medium Primary function; reads DeepSeek chat content.
  • host:*.googleusercontent.com low Google-hosted assets; read-only images/fonts typical.
  • host:ai-chat-exporter-api-deepseek-* high Developer-controlled backend receives chat data; opaque pipeline.
  • host:api.dropboxapi.com + content.dropboxapi.com medium Cloud upload integration; requires OAuth token.
  • host:api.notion.com medium Notion export integration; appropriate but widens surface.
  • host:cloud-api.yandex.net + oauth.yandex.* medium Yandex cloud integration; Russian CDN geo-risk consideration.
  • host:www.googleapis.com low Standard Google API endpoint for Drive/identity.

Pillar Scores

Permissions3.50
Reputation7.00
Network3.50
Webstore6.50
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 13:32
Listing SHA d09c800aec9c…
Force block — not fired
Score recovered no
Elapsed