Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Annotate pdf

ffkgggpfimdabhlfomcfhpgbmjfdbhfh
Risk Score
4.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 60,000
Rating 4.2
Last updated 2025-03-12 (15 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@annotatepdf.io
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; data collection and 3rd-party sharing admitted.
  • <all_urls> host_permissions + scripting allows code injection on every site the user visits.
  • Dynamic script creation (script_src_dynamic) in bundled JS can load remote code at runtime.
  • Content script injected into Google Search (beyond PDF scope) — unexplained scope expansion.
  • install_url_hijack and uninstall_url_hijack flags set; no target URL captured but pattern is concerning.

Evidence

  • privacy_policy_generic store PP URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection+3rd_party_sharing=true → +10.0 privacy.
  • script_src_dynamic crx Two JS chunks create dynamic <script> elements — runtime script loading risk.
  • host_permissions_all_urls manifest <all_urls> combined with scripting permission = high-capability injection surface.
  • content_script_scope_mismatch manifest content_scripts include https://www.google.com/search* — not justified by PDF annotation category.
  • install_uninstall_url_hijack store install_url_hijack=true and uninstall_url_hijack=true; targets null but flags raised.
  • external_hosts crx 6 external JS hosts: fonts.googleapis.com, fonts.gstatic.com, nextjs.org, pdfedit.ai, reactjs.org, use.typekit.net.
  • developer_name_missing store developer_name is empty string; reputation penalized; verified_publisher=true applies floor.
  • maintenance_stale store months_since_update=15 (6-12mo band exceeded); 12-24mo band → +6.0 maintenance pillar.

Permissions Breakdown

  • scripting medium Can inject scripts into pages; paired with <all_urls> host permission, elevates risk significantly.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • <all_urls> (host_permissions) high Broad host access across all URLs; combined with scripting creates high-capability surface.
  • content_scripts: http://*/*.pdf, https://*/*.pdf medium Scoped to PDF files — reasonable for stated function, but also injects into Google Search.
  • content_scripts: https://www.google.com/search* medium Injecting into Google Search results goes beyond PDF annotation scope.

Pillar Scores

Permissions5.50
Reputation3.50
Network3.50
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA 5bd875dd15d0…
Force block — not fired
Score recovered no
Elapsed 36.1s