Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GitHub Helper

egagonnbmdaflafonhmipdblcdfbfcki
Risk Score
4.35
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 6
Rating
Last updated 2025-09-24 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer panchal.rajan2k19@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy (scope_extension=false, admits data collection and 3rd-party sharing) — scores maximum privacy risk.
  • Brand impersonation: extension mentions 'github' but developer is an unverified free-webmail user with no business identity.
  • Free-webmail developer (gmail), no developer name, no verified publisher — high reputation risk.
  • innerHTML DOM-XSS sink in button-utils.js with no CSP — amplified code quality risk.
  • No CSP on MV3 extension with DOM-manipulation sink raises XSS exploitability.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[github]; confirmed_owner=false; developer on gmail.com.
  • generic_privacy_policy api Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • dom_xss_sink_no_csp crx innerHTML assignment in button-utils.js; csp_present=false amplifies DOM-XSS risk.
  • free_webmail_no_dev_name store developer_email=panchal.rajan2k19@gmail.com; developer_name empty; no business website.
  • no_csp_mv3 manifest content_security_policy=null; MV3 default strict but no explicit CSP; +2.0 network per v2 rule.
  • very_low_installs store Only 6 installs; blast radius minimal but tail-attack surface anomaly not flagged.
  • cve_findings_empty crx No CVEs detected in bundled JS libraries; cve_pillar_score=0.0.
  • maintenance_3_6mo store months_since_update=9; falls in 6-12mo band → +3.5 maintenance.

Permissions Breakdown

  • storage low Local key-value persistence only; no cross-origin or user-data exfil risk.
  • content_scripts on https://github.com/* low Scoped to a single origin (github.com); DOM access limited to that site.

Pillar Scores

Permissions0.50
Reputation8.00
Network2.00
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 7ed3c989d255…
Force block — not fired
Score recovered no
Elapsed 24.0s