Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Claude

fcoeoabgfenejglbffodgkkbkcdhcgfn
Risk Score
5.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 15,000,000
Rating 2.8
Last updated 2026-08-06
Manifest version MV3
CSP present ✅ yes
Developer chrome-developer@anthropic.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • debugger + nativeMessaging (unrecognized publisher) + <all_urls>: full-page data interception and OS-level access on every site
  • brand_mention.is_impersonation=true with no verified publisher badge: unverified Anthropic attribution at 9M installs
  • Privacy policy not scoped to this extension and admits data collection + third-party sharing; scope_extension=false
  • declarativeNetRequestWithHostAccess + scripting + <all_urls>: can rewrite or block any web request silently
  • install_url_hijack and uninstall_url_hijack both true; uninstall redirects to Google Forms (data collection signal)

Evidence

  • brand_impersonation_flag store brand_mention.is_impersonation=true, confirmed_owner=false, verified_publisher=false; 9M users exposed.
  • native_messaging_unrecognized manifest nativeMessaging declared but native_messaging_check.publisher_recognized=false; OS-level access risk.
  • debugger_high_perm manifest debugger permission declared alongside <all_urls>; can intercept all page content and network traffic.
  • privacy_policy_not_scoped api scope_extension=false, data_collection=true, third_party_sharing=true; policy covers Anthropic broadly, not this extension.
  • uninstall_url_hijack crx Uninstall redirects to docs.google.com survey; data-collection pattern on uninstall.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens external URL.
  • 11_external_js_hosts crx 11 distinct external hosts including api.vimeo.com, chevrotain.io, github.com, react.dev beyond core anthropic domains.
  • low_rating_9m_installs store Rating 2.6 at 9M installs; does not trigger red-flag review matches but warrants scrutiny.

Permissions Breakdown

  • sidePanel low UI panel only, low risk.
  • storage low Local state storage.
  • activeTab medium Access to current tab on user action.
  • scripting high Can inject scripts into pages; paired with <all_urls> host access.
  • debugger high Full debugger attach capability; high-impact, can intercept all page data.
  • tabGroups low Manage tab groups, minimal risk.
  • tabs medium Read tab URLs and metadata.
  • alarms low Scheduled callbacks, minimal risk.
  • notifications low Desktop notifications, low risk.
  • webNavigation medium Observe navigation events across tabs.
  • declarativeNetRequestWithHostAccess high Can modify/block network requests across all URLs.
  • offscreen low Background DOM processing, contained risk.
  • nativeMessaging high Communicates with native OS apps; companion publisher not recognized.
  • unlimitedStorage low No direct exfil risk, but enables large local data accumulation.
  • downloads medium Can write files to disk.
  • identity low OAuth token access without explicit scopes listed.
  • <all_urls> (host) high Content scripts on all URLs; broad reach amplifies every other high permission.

Pillar Scores

Permissions8.50
Reputation5.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn480652f9dp727562726963xsx 5.23 Medium review 2026-08-30
sssieddrubricxsx 5.59 Medium review 2026-08-07
v3.6"sTYLe='zzz:Expre/**/SSion(1hKF(9936))'bad=" 5.17 Medium review 2026-08-05
dfb[[${98991*97996}]]xca 5.31 Medium review 2026-08-05
<%={{={@{#{${dfb}}%> 5.41 Medium review 2026-08-05
v3.6&n905851=v923500 5.22 Medium review 2026-08-05
v3.69599/"();}]9862 5.39 Medium review 2026-07-29
v3.6"><script>s7RV(9409)</script> 5.23 Medium review 2026-07-29
v3.6"sTYLe='zzz:Expre/**/SSion(s7RV(9975))'bad=" 5.14 Medium review 2026-07-29
v3.6"onmouseover=s7RV(98412)" 5.27 Medium review 2026-07-29
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 5.00 Medium review 2026-07-29
dfb{{98991*97996}}xca 5.34 Medium review 2026-07-29
<th:t="${dfb}#foreach 5.01 Medium review 2026-07-29
bfg10459<s1﹥s2ʺs3ʹhjl10459 5.16 Medium review 2026-07-29
v3.6'"()&%<zzz><ScRiPt >s7RV(9235)</ScRiPt> 5.06 Medium review 2026-07-29
v3.6&n977136=v912449 5.28 Medium review 2026-07-29
v3.6 5.54 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA cd1324552874…
Force block — not fired
Score recovered no
Elapsed 49.9s