Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Note Everywhere

fjfoncfdjhdefjhknbaphionnognbnpl
Risk Score
4.67
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 20,000
Rating 4.4
Last updated 2026-05-05 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer takumibv@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but admits data collection and third-party sharing without extension-specific scope — scores maximum privacy risk.
  • Developer uses free Gmail address with minimal identity ('bv'); no business domain or verified publisher status.
  • scripting + <all_urls>: extension can inject JS into every page the user visits.
  • install_url_hijack and uninstall_url_hijack flags present; targets are null but flag indicates hook is in place.
  • No CSP present on MV3 extension with external JS host (react.dev) referenced.

Evidence

  • privacy_policy_admits_3rd_party_sharing_no_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • free_webmail_developer store Developer email takumibv@gmail.com, name 'bv' — free webmail, no business domain; reputation floor >=7.5 per rubric.
  • scripting_plus_all_urls manifest scripting permission combined with <all_urls> host permission enables arbitrary JS injection on any site.
  • install_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets null so no confirmed 3rd-party redirect, but hooks present.
  • no_csp manifest content_security_policy is null; MV3 has strict default but explicit CSP absent; external host react.dev referenced.
  • featured_by_google store is_featured_by_google=true; partial trust signal applied to reputation.
  • no_bad_hosts_no_cves api bad_host_hits=[], cve_findings_raw=[], obfuscation_score=0.0, code_findings_raw=[] — no active malicious indicators.
  • recently_updated store months_since_update=1; maintenance pillar=0.0.

Permissions Breakdown

  • storage low Core for saving notes; low risk.
  • unlimitedStorage low Extended quota for note data; low risk.
  • scripting high Can inject JS into any page via <all_urls>; high capability risk.
  • tabs medium Can read tab URLs and metadata; moderate privacy risk.
  • contextMenus low Adds right-click menu entries; minimal risk.
  • <all_urls> (host_permission) high Broad access to all sites; combined with scripting, can read/modify any page.

Pillar Scores

Permissions6.00
Reputation7.00
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA 4cc5c6438390…
Force block — not fired
Score recovered no
Elapsed 22.6s