Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Woobie

eicibdbdaedbgaoikodgpoikeegncpag
Risk Score
3.57
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 66
Rating
Last updated 2026-06-25 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer joe@woobie.io
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL is unreachable (fetch error); no policy classification possible — scored as no policy (+10.0).
  • Content script runs on all va.gov pages, accessing potentially sensitive veteran health/claims data.
  • No developer name listed; small install base (66) with no ratings limits reputation signal.
  • AI assistant extension processing VA.gov page content raises data-handling concerns without verifiable privacy policy.
  • MV3 + no CSP: v2 calibration +2.0 network penalty applies; all JS hosts are US-only and dev-controlled (mitigates).

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL https://woobie.io/privacy-policy/ returned HTTPError; treated as no policy fetched.
  • content_script_sensitive_domain manifest content_scripts_matches: *://*.va.gov/* — injects into US government VA pages with veteran PII.
  • no_developer_name store developer_name is empty string; only email joe@woobie.io available for identity verification.
  • very_low_install_count store Only 66 installs, 0 ratings — very limited adoption; reputation signals are weak.
  • no_cve_findings crx cve_findings_raw is empty; no known vulnerable JS libraries detected.
  • clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, 6 JS files scanned — no malicious indicators.
  • threat_intel_clean api No bad_host_hits, monetization_hits, or affiliate_hits; developer domain resolves, not throwaway.
  • ai_extension_va_gov manifest Description states AI assistant for claim/status help while browsing; AI processing on gov site.

Permissions Breakdown

  • activeTab low Grants access to current tab only on user action; scoped and low blast radius.
  • identity low Used for OAuth/Cognito auth flow; no broad scope requested.
  • storage low Local extension storage; no cross-site data exposure.
  • host:amazoncognito.com low AWS Cognito auth endpoint; scoped to dev's auth service.
  • host:auth.dev-myra.woobie.io low Dev-owned subdomain for auth; scoped.
  • host:cognito-idp.us-west-2.amazonaws.com low AWS Cognito IDP; standard auth backend.
  • host:api.woobie.io low Dev-owned API; scoped to stated function.
  • host:app.woobie.io low Dev-owned app domain; scoped.
  • host:dev-app.woobie.io low Dev staging domain; low risk.
  • host:api.va.gov medium Government VA API; content scripts run on va.gov — handles sensitive veteran data.
  • content_scripts:*://*.va.gov/* medium Injects into all VA.gov pages; accesses sensitive veteran claim/health data in DOM.

Pillar Scores

Permissions2.00
Reputation6.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 15:58
Listing SHA c6e79133298e…
Force block — not fired
Score recovered no
Elapsed