Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VnChatGPT

fkfilegpkbdejgolppocomljgjmfllim
Risk Score
4.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override sets vnchatgpt.com as default engine, routing all user queries through an unverified operator.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • No developer identity (name, email, domain) — zero accountability; anonymous publisher.
  • No update date or install count available — extension provenance entirely unverifiable.
  • AI-branded extension with search override: high potential for query harvesting and monetization without disclosure.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets VnChatGPT as default search engine; all queries routed to vnchatgpt.com.
  • generic_google_privacy_policy store Privacy policy URL is Google account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_developer_identity store developer_name and developer_email both empty; no verified publisher; no 'Offered by' info.
  • missing_store_metadata store installs, rating, last_updated all null — cannot assess reach or maintenance.
  • content_script_narrow manifest content_scripts limited to https://*.vnchatgpt.com/* — operator's own domain only.
  • no_cve_findings crx cve_findings_raw empty; no CVE exposure detected.
  • no_bad_hosts crx threat_intel.bad_host_hits and monetization_hits empty; js_external_hosts empty.
  • obfuscation_clean crx obfuscation_score=0.0; code_findings_raw empty; 1 JS file scanned with no findings.

Permissions Breakdown

  • chrome_settings_overrides.search_provider (is_default=true) medium Overrides default search engine to vnchatgpt.com; high-impact UX change, routes all searches through operator.
  • content_scripts on https://*.vnchatgpt.com/* low Narrow host scope limited to operator's own domain; low lateral reach.

Pillar Scores

Permissions3.00
Reputation7.50
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 16:08
Listing SHA 60cbe98c595a…
Force block — not fired
Score recovered no
Elapsed