Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Meta Ads Data Advisor

fdgfkebogiimcoedlicjlajpkdmockpc
Risk Score
3.96
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 3,000,000
Rating 3.9
Last updated 2026-09-02
Manifest version MV3
CSP present ❌ no
Developer extensions@fb.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • debugger + cookies + <all_urls> combo gives full runtime control and cookie access on every site
  • brand_mention.is_impersonation=true for 'meta' but verified_publisher=false — unverified Meta branding
  • Privacy policy is Facebook's generic corporate policy; scope_extension=false means THIS extension's data practices undisclosed
  • No CSP (csp_present=false) with innerHTML sinks in bundled React vendor — DOM-XSS risk on extension pages
  • install_url_hijack=true: onInstalled opens a third-party URL

Evidence

  • high_perm_combo manifest debugger + cookies + webRequest + scripting + <all_urls>: full-page observation and runtime control on every site.
  • brand_impersonation store brand_mention.is_impersonation=true for 'meta'; developer not verified_publisher nor is_featured_by_google=true resolves discount.
  • privacy_policy_not_scoped api Policy is facebook.com corporate page; scope_extension=false, data_collection=false — generic, not extension-specific.
  • no_csp manifest content_security_policy=null on MV3 extension with innerHTML sinks in React vendor bundle.
  • install_url_hijack crx install_url_hijack=true; target URL not captured but onInstalled opens external page.
  • dom_xss_sink crx Two dom_sink_innerhtml_userctrl findings in react-vendor bundle; no CSP amplifies risk.
  • looks_throwaway_domain api threat_intel developer_domain fb.com flagged looks_throwaway=true despite being a known Meta domain.
  • webstore_install_count store 3,000,000 installs — high blast radius if extension is compromised or mis-attributed.

Permissions Breakdown

  • storage low Local state persistence; low standalone risk.
  • scripting high Injects scripts into pages; paired with <all_urls> is high impact.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • activeTab low Transient access to active tab only; less risky alone.
  • unlimitedStorage low Allows large local data accumulation; low direct risk.
  • webNavigation medium Monitors navigation events across all pages.
  • cookies high Combined with <all_urls>: can read/write cookies on any domain. ×1.2 multiplier.
  • webRequest high Can observe all HTTP requests on every site visited.
  • alarms low Background scheduling only; minimal standalone risk.
  • debugger high Full JS runtime control, network interception, breakpoints on any tab.
  • tabGroups low Tab grouping UI only; low risk.
  • identity low OAuth token acquisition; no scopes declared reduces risk.
  • sidePanel low UI surface only; low standalone risk.
  • <all_urls> high Broad host access enabling content scripts and API calls on every site.

Pillar Scores

Permissions8.50
Reputation5.50
Network2.50
Webstore4.50
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiednaf383673dp727562726963xsx 5.76 Medium review 2026-09-07
sssieddrubricxsx 4.33 Medium review 2026-08-02
%76%33%2E%36%39%36%38%39%22%28%29%3B%7D%5D%39%31%37%31 4.18 Medium review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 3.96 Low review 2026-07-29
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 3.02 Low review 2026-07-29
dfb__${98991*97996}__::.x 5.23 Medium review 2026-07-29
dfb{{98991*97996}}xca 4.57 Medium review 2026-07-29
v3.6'"()&%<zzz><ScRiPt >eXGc(9585)</ScRiPt> 4.09 Medium review 2026-07-29
v3.6&n982464=v950785 4.29 Medium review 2026-07-29
v3.6 3.96 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA 27ed64b7edfa…
Force block — not fired
Score recovered no
Elapsed 29.1s