Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Save as Shortcut

flehofiklehmnnolpjcamplcnmhgcbkk
Risk Score
4.82
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 10,000
Rating 4.5
Last updated
Manifest version MV3
CSP present ❌ no
Developer hello@mythofechelon.co.uk
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • last_updated is null/unknown — maintenance state cannot be assessed, defaulting to worst case.
  • new Function() in bundled jszip.min.js is a code-execution risk if fed attacker-controlled input.
  • No CSP declared (MV3 mitigates somewhat, but js_external_hosts include 5 distinct domains).
  • Developer name missing; privacy policy not scoped to extension raises accountability gap.

Evidence

  • privacy_policy_generic store Policy URL is Google's own account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • maintenance_unknown store last_updated is empty string; months_since_update is null — treated as >36 months per conservative policy.
  • function_constructor_in_jszip crx new Function() found in js/jszip.min.js; common in zip libraries but elevates code-quality risk.
  • no_csp manifest content_security_policy is null; MV3 default helps but 5 external JS hosts noted.
  • verified_publisher store verified_publisher=true; developer domain mythofechelon.co.uk resolves and is not throwaway.
  • no_bad_hosts_no_affiliates api threat_intel shows empty bad_host_hits, affiliate_hits, and monetization_hits.
  • no_cve_findings crx cve_findings_raw is empty; no known-vulnerable library versions detected.
  • developer_name_missing store developer_name field is empty string; only email hello@mythofechelon.co.uk available.

Permissions Breakdown

  • activeTab low Grants access to the current tab only on user action; limited scope.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • bookmarks medium Read/write access to user's full bookmark tree.
  • storage low Local extension storage only; no cross-origin exposure.
  • scripting medium Can inject scripts into pages; risk mitigated by no broad host_permissions.

Pillar Scores

Permissions2.90
Reputation2.00
Network2.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA 234d6c9c67e6…
Force block — not fired
Score recovered no
Elapsed 23.2s