Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ArkheVault Realm Resolver

eokkbmoflgpfigececbpdndmfjilhgoo
Risk Score
3.28
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 4
Rating
Last updated 2026-07-18 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer name@arkhevault.nmwyhwh.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Content scripts injected on <all_urls> combined with scripting permission gives broad page-level read/write capability.
  • Developer identity is an opaque subdomain alias (nmwyhwh); no verified publisher badge; throwaway-style naming.
  • Install-on-open URL hijack (install_url_hijack=true) redirects users to an unverified third-party page on install.
  • Privacy policy admits third-party sharing (third_party_sharing=true) but no data collection or retention disclosed.
  • Localhost host_permission (localhost:3001) enables probing of local services on the user's machine.

Evidence

  • content_scripts_all_urls manifest content_scripts_matches=["<all_urls>"] — scripts run on every page the user visits.
  • install_url_hijack store install_url_hijack=true; extension opens a URL on install to an unverified target.
  • localhost_host_permission manifest host_permissions include http://localhost:3001/api/* enabling local service enumeration.
  • opaque_developer_identity store Developer name 'nmwyhwh' and email on subdomain of same; no verified publisher; no recognizable org.
  • third_party_sharing_disclosed api privacy_policy_classification: third_party_sharing=true, data_collection=false, retention=false.
  • very_low_install_count store Only 4 installs; no ratings; zero community validation.
  • csp_present_mv3 manifest CSP script-src 'self'; object-src 'self' — good hygiene for MV3.
  • no_cve_no_obfuscation crx cve_findings_raw empty; obfuscation_score=0.0; code_findings_raw empty — clean scan.

Permissions Breakdown

  • storage low Standard local state persistence.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • notifications low Desktop notifications; low risk.
  • scripting medium Programmatic script injection; elevated when paired with <all_urls> content scripts.
  • sidePanel low Opens a persistent side panel; UI only.
  • host_permissions: https://api.nmwyhwh.com/api/* medium Scoped to dev API; unknown server trustworthiness.
  • host_permissions: https://arkhevault.nmwyhwh.com/api/* medium Scoped to dev domain; same trust concern.
  • host_permissions: http://localhost:3001/api/* medium Localhost access could probe local services on user machine.
  • content_scripts_matches: <all_urls> high Content scripts inject into every page visited; broad read/write surface.

Pillar Scores

Permissions4.50
Reputation6.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:26
Listing SHA ebb4eaed836c…
Force block — not fired
Score recovered no
Elapsed