Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cherry Lake

emglghamljaiaepkjkfmhgbjfihphgfg
Risk Score
5.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 9
Rating
Last updated 2026-05-11 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijack both redirect to gameograf.com affiliate/UTM URL — monetization shell pattern.
  • Privacy policy URL returns fetch error (ConnectionError) — effectively no accessible privacy policy.
  • NewTab override combined with search permission and operator cluster of 50 dev-email siblings signals traffic-monetization operation.
  • No CSP present (MV3 so no v2 bonus penalty, but dom_sink_innerhtml_userctrl findings elevate XSS risk).
  • Developer name absent; verified publisher discount limited by monetization signals per invariant 0c.

Evidence

  • install_url_hijack + uninstall_url_hijack manifest Both install and uninstall redirect to gameograf.com with UTM/affiliate params — monetization shell.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false, reason=fetch_error:ConnectionError — policy inaccessible.
  • operator_cluster_dev_email_siblings api dev_email dimension shows 50 sibling extensions under support@gameograf.com.
  • newtab_override manifest chrome_url_overrides.newtab present; extension replaces every new tab page.
  • dom_sink_innerhtml_userctrl crx Two DOM-XSS sinks in popup.js and calendar.js; no CSP to mitigate.
  • operator_cluster_compound_sibling api compound fingerprint sibling_count=1 (lnagjecldcpfmlcgliojbhehighibhkj) — template-stamped extension pair.
  • verified_publisher_with_monetization store verified_publisher=true but install/uninstall URL hijacks present — invariant 0c caps discount at -1.0.
  • developer_name_absent store developer_name is empty string — accountability gap despite verified publisher badge.

Permissions Breakdown

  • search medium Allows overriding search provider — monetization vector for NewTab extensions.
  • host_permissions: https://api.gameograf.com/* low Scoped to dev's own API domain; limited blast radius.
  • chrome_url_overrides.newtab medium Replaces new tab page — high visibility surface, common monetization shell.

Pillar Scores

Permissions3.00
Reputation5.00
Network0.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Operator Siblings (1)

Other extensions sharing this developer's compound fingerprint:

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 07:38
Listing SHA b37fda2b0273…
Force block — not fired
Score recovered no
Elapsed