Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Knowee AI (formerly StudyGPT) - Your Homework & Essay Helper

fcejkolobdcfbhhakbhajcflakmnhaff
Risk Score
6.12
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs 30,000
Rating 4.8
Last updated 2026-04-23 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer service@xbuddy.ai
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (Arbitrary Code Execution) with no CSP amplifier active on MV3.
  • cookies + <all_urls> + scripting combo enables full credential/session theft across all sites.
  • No CSP present + multiple innerHTML sinks in 5 content scripts + function_constructor = broad XSS surface.
  • Developer domain xbuddy.ai does not resolve; verified-publisher discount capped to -1.0 per invariant 0c.
  • uninstall_url_hijack and install_url_hijack both flagged; indicates tracking/redirect behaviour on lifecycle events.

Evidence

  • critical_cve crx underscore@1.8.3 bundled in googleDocs.js; CVE-2021-23358 Arbitrary Code Execution (fixed in 1.12.1).
  • high_cve crx underscore@1.8.3; CVE-2026-27601 DoS via unbounded recursion (fixed in 1.13.8).
  • csp_absent manifest content_security_policy is null; MV3 default applies but no explicit CSP hardens against CVE+innerHTML risks.
  • dom_xss_sinks crx innerHTML assignment from variable found in 5 content-scripts (content.js, googleDocsGuide.js, localPdfTips.js, selection.js, youtube.js).
  • function_constructor crx new Function() in pages/pdf/build/pdf.js and pdf.worker.js; dynamic code execution risk.
  • lifecycle_hijack manifest uninstall_url_hijack=true and install_url_hijack=true; extension registers redirect/tracking on install and uninstall.
  • developer_domain_non_resolving api xbuddy.ai (dev email domain) does not resolve per threat_intel; caps verified-publisher discount to -1.0.
  • ai_page_content store AI extension with <all_urls> content scripts processes arbitrary page content for homework/essay generation.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Exposes URL/title of all open tabs across browsing session.
  • storage low Local key-value storage; standard.
  • cookies high Can read/write cookies on any domain when paired with <all_urls>.
  • activeTab low Scoped to user-triggered action; low standalone risk.
  • scripting high Programmatic script injection into any page via broad host access.
  • <all_urls> high Unrestricted host access; highest-reach surface.
  • file://* high Access to local filesystem via file:// protocol; unusual for AI tool.
  • http://*/* high Duplicate broad host; redundant with <all_urls>.
  • https://*/* high Duplicate broad host; redundant with <all_urls>.

Pillar Scores

Permissions8.00
Reputation4.00
Network4.50
Webstore5.50
Maintenance1.50
Privacy2.00
Code Quality6.50
CVE Exposure10.00

Scoring History

sssiedn3dcdaaf7dp727562726963xsx 5.47 Medium review 2026-09-14
v3.6 6.12 High block 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:01
Listing SHA e09610938fcb…
Force block — not fired
Score recovered no
Elapsed