Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Search GPT for Chrome

fmncmpginchogfdnjfeopdopoiegjjjp
Risk Score
6.10
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category AI
Installs 10,000
Rating 4.8
Last updated 2025-11-25 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer chrismartiner.90@hotmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Hotmail dev email + generic AI-tools name: unverifiable developer identity with no accountability.
  • Privacy policy is Google's own policy — does not disclose what THIS extension collects; scope_extension==false, data_collection==true, third_party_sharing==true.
  • Broad host_permissions *://*/* + content_scripts on all Google TLDs expose every search query to extension code.
  • External host chat.searchaitool.net contacted — unknown third-party AI backend with no disclosed data handling.
  • AI extension processing search-page content at scale (10K+ users) with opaque backend and inadequate privacy disclosures.

Evidence

  • free_webmail_developer store Developer email chrismartiner.90@hotmail.com is a free webmail address; no verifiable business identity.
  • generic_privacy_policy store Privacy URL points to Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • broad_host_permissions manifest host_permissions *://*/* plus content_scripts on 200+ Google TLDs and major search engines.
  • unknown_ai_backend crx js_external_hosts includes chat.searchaitool.net — third-party AI backend with no disclosed ownership or data policy.
  • function_constructor crx new Function() constructor in libs/math.min.js; low obfuscation score but dynamic code execution path present.
  • no_csp manifest content_security_policy is null; MV3 default helps but no explicit CSP reduces defence-in-depth.
  • ai_extension_page_content store AI extension injecting into all search pages; processes user search queries and sends to external backend.
  • install_count_threshold store 10,000 installs with free-webmail unverified developer and inadequate privacy policy increases blast radius.

Permissions Breakdown

  • storage low Local key-value storage only; low inherent risk.
  • host_permissions: *://*/* high Broad host access grants content-script read/write on every site visited.
  • content_scripts: *://*/*oogle.*/search + major engines high Runs code on all Google TLDs and major search engines; reads user search queries.

Pillar Scores

Permissions7.00
Reputation7.50
Network4.50
Webstore4.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:05
Listing SHA df485d933d09…
Force block — not fired
Score recovered no
Elapsed