Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ejhhhokbkmlibaeoepkohaflgaohpmeg

ejhhhokbkmlibaeoepkohaflgaohpmeg
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs
Rating
Last updated
Manifest version MV3
CSP present ✅ yes
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Developer-controlled Cloud Run backend (ai-chat-exporter-api-github-copilot-*.run.app) is the primary exfiltration surface for AI chat content.
  • 8 DOM-XSS innerHTML sinks across content scripts on copilot.microsoft.com and github.com increase XSS attack surface.
  • No developer identity (name, email, domain) — unverifiable publisher with no accountability.
  • CSP connect-src allows wildcard '*' on extension pages — permits outbound connections to any host.

Evidence

  • privacy_policy_generic_google store Privacy URL is Google's own account policy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • developer_controlled_backend manifest Host perm to ai-chat-exporter-api-github-copilot-792277256340.northamerica-south1.run.app; also in js_external_hosts.
  • csp_connect_src_wildcard crx extension_pages CSP: connect-src * — allows extension to connect to any host at runtime.
  • no_developer_identity store developer_name, developer_email, and developer_domain all empty/null — reputation floor 7.5 (free-webmail-like).
  • install_url_hijack crx install_url_hijack=true — opens a URL on install; target is null so destination unverifiable.
  • dom_xss_sinks_multiple crx 8 innerHTML-from-variable findings across content scripts and lib files without CSP script-src restrictions.
  • external_hosts_diversity crx 12 distinct external JS hosts including stripe, grok, deepseek, neocortexai.in, chatgpt.com — broad surface.
  • maintenance_unknown store last_updated and months_since_update both null — maintenance state unknown, scored 0.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • downloads medium Can trigger file downloads to user's machine.
  • downloads.open medium Can auto-open downloaded files; elevates downloads risk.
  • identity low OAuth token access; scoped to user consent flows.
  • activeTab low Scoped to user-initiated action on current tab only.
  • host:*.amazonaws.com medium Broad AWS bucket access; could interact with many S3 services.
  • host:*.googleusercontent.com medium Access to Google user content CDN.
  • host:ai-chat-exporter-api-github-copilot-*.run.app high Calls a developer-controlled backend API — primary exfil surface.
  • host:api.dropboxapi.com + content.dropboxapi.com medium Dropbox API access; can read/write user cloud storage.
  • host:api.github.com + github.com medium GitHub API and site access; can read repos/gists.
  • host:api.notion.com medium Notion workspace API; can read/write user notes.
  • host:cloud-api.yandex.net + oauth.yandex.* medium Yandex cloud and OAuth; cross-jurisdiction data flow.
  • host:copilot.microsoft.com + copilot.com low Expected for AI chat exporter targeting Copilot.
  • host:www.googleapis.com low Standard Google APIs used with identity permission.

Pillar Scores

Permissions3.30
Reputation7.50
Network4.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 13:30
Listing SHA e8105ee0541b…
Force block — not fired
Score recovered no
Elapsed