Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Vector Vault

faedpdgepbjjlmeiiapjflihlbcppdhg
Risk Score
3.17
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 6
Rating
Last updated 2026-07-09 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer zerovectorti@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google's generic privacy policy is not scoped to this extension; data handling for user credentials is undisclosed.
  • Free-webmail developer (gmail) with no developer name or verified business identity.
  • Password manager accessing clipboard and injecting scripts — high-value target if compromised.
  • No privacy policy scoped to this extension despite handling authentication credentials.
  • Very low install count (6) makes reputation signals unreliable; unproven in the wild.

Evidence

  • privacy_policy_generic store Privacy policy URL points to Google's own account policy, not scoped to this extension or its data handling.
  • free_webmail_dev_no_name store Developer email zerovectorti@gmail.com; developer_name is empty; no verified business identity.
  • no_code_findings crx 2 JS files scanned; code_findings_raw empty; obfuscation_score 0.0 — no malicious indicators detected.
  • host_permission_scoped manifest Single host permission vault.umbrellacloud.com.br; no broad host access; geo: CA only.
  • no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
  • no_bad_hosts api threat_intel bad_host_hits, monetization_hits, and affiliate_hits all empty.
  • privacy_policy_admits_third_party store Fetched policy has data_collection=true, third_party_sharing=true but scope_extension=false — v3.5(D) applies: +10.0.
  • mv3_no_csp manifest Manifest version 3 with no explicit CSP; MV3 enforces strict default so no +2.0 MV2 penalty applies.

Permissions Breakdown

  • storage low Standard local data persistence; low risk for a password vault extension.
  • activeTab medium Accesses current tab on user action; needed for auto-fill but limited to active tab only.
  • scripting medium Can inject scripts into pages; necessary for auto-fill but elevates capability.
  • clipboardWrite medium Can write to clipboard; expected for password managers copying credentials.
  • https://vault.umbrellacloud.com.br/* medium Scoped host access to single vault domain; appropriate for a password vault fetching credentials.

Pillar Scores

Permissions2.30
Reputation7.00
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:41
Listing SHA 8d35b2517449…
Force block — not fired
Score recovered no
Elapsed