Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Privacy Guard & Manager

fnodegploiacnbekfkhflfmgmpncjjib
Risk Score
4.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 2,000
Rating 4.5
Last updated 2025-10-06 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer muyu.biovie@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL is the extension's own store listing page — not a real policy; classified as generic/non-scoped.
  • Developer uses free Gmail address with no verifiable business identity.
  • install_url_hijack and uninstall_url_hijack flags are true (targets null but hooks are present).
  • 'privacy' permission allows direct manipulation of core browser privacy/security controls.
  • No CSP present (MV3 mitigates partially, but js_external_hosts include github.com and webbrowsertools.com).

Evidence

  • privacy_policy_points_to_store_listing store Privacy policy URL resolves to the extension's own Chrome Web Store page — not a dedicated policy document.
  • free_webmail_developer store Developer email muyu.biovie@gmail.com is a free Gmail account; no verified business domain.
  • install_and_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; target URLs are null but hooks are wired.
  • privacy_permission_high_capability manifest 'privacy' permission grants control over browser-wide privacy settings (DNT, referrer, tracking protection).
  • external_js_hosts crx Extension references github.com and webbrowsertools.com as external JS hosts; no CSP to constrain them.
  • featured_by_google store Extension carries 'Featured' badge from Google, providing partial trust signal.
  • no_cve_findings crx cve_findings_raw is empty; no vulnerable bundled libraries detected.
  • no_code_findings crx code_findings_raw is empty; no eval, exfil, or obfuscation detected (obfuscation_score=0.0).

Permissions Breakdown

  • storage low Persists user preferences locally; minimal risk.
  • privacy high Controls browser privacy settings (tracking protection, referrer policy, etc.) — sensitive capability.

Pillar Scores

Permissions3.50
Reputation6.50
Network2.00
Webstore5.50
Maintenance3.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA 992e06aaa2f5…
Force block — not fired
Score recovered no
Elapsed 18.5s