Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

eoolfmmapnkhandljfaaofncecfakljd

eoolfmmapnkhandljfaaofncecfakljd
Risk Score
4.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Content script on all URLs combined with no CSP; 4 innerHTML DOM-XSS sinks across injection files.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • No developer identity (no name, no email, no verified publisher); extension cannot be attributed.
  • Contacts gsg-extension.com and pepper.com endpoints whose ownership is unverifiable given missing developer info.
  • Maintenance data entirely missing; update cadence and lifecycle accountability unknown.

Evidence

  • content_scripts_broad manifest content_scripts_matches covers http://*/* and https://*/* — full browse-history injection surface.
  • no_csp manifest csp_present=false on MV3 extension; no Content-Security-Policy declared despite broad content scripts.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_developer_identity store developer_name, developer_email, and title all empty; no attribution possible.
  • dom_xss_sinks crx 4 innerHTML-from-variable sinks in injection-root.js, injection-serp.js, settings.js, window.js; no CSP mitigates.
  • external_hosts crx 12 external JS hosts including caa-configurations.gsg-extension.com, ocular-xtn.pepper.com, logs.browser-intake-datadoghq.eu.
  • maintenance_unknown store last_updated and months_since_update are null; no update history available.
  • manifest_name_unresolved manifest manifest_name is __MSG__extensionName__; localized name not resolved, title field empty in listing.

Permissions Breakdown

  • alarms low Schedules periodic tasks; low risk alone.
  • storage low Stores extension preferences locally.
  • tabs medium Can read tab URLs and titles; moderate privacy surface.
  • unlimitedStorage low Allows large local data; no exfil risk by itself.
  • content_scripts http://*/* https://*/* high Injects JS into every page; broad capability even without declared host_permissions.

Pillar Scores

Permissions3.30
Reputation7.00
Network3.50
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-06 05:33
Listing SHA 01439e6c32fd…
Force block — not fired
Score recovered no
Elapsed