Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Onion Browser Button

fockhhgebmfjljjmjhbdgibcmofjbpca
Risk Score
5.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 20,000
Rating 3.4
Last updated 2025-07-23 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer sevina.lucia@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic rerouting by any future malicious update from an unverifiable gmail developer.
  • Free-webmail developer (gmail) with no verified business identity; no accountability path if extension is sold or compromised.
  • install_url_hijack and uninstall_url_hijack flags set; targets unresolvable (null) but pattern is suspicious.
  • Privacy policy scoped but lacks data-retention disclosure and silences third-party sharing.
  • Rating 3.4 from a privacy/proxy tool; community dissatisfaction with a high-capability permission is a risk signal.

Evidence

  • proxy_permission manifest proxy declared — can redirect all browser traffic; justified for TOR proxy tool but extreme if developer account is compromised.
  • free_webmail_developer store Developer email sevina.lucia@gmail.com; no verified business domain; Reputation pillar floored at 7.5 per rubric.
  • install_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets are null so full impact unclear but pattern is risky.
  • no_csp manifest content_security_policy is null; MV3 has strict default but absence of explicit CSP noted.
  • privacy_policy_retention_missing api Policy fetched, scoped, no data_collection, but retention=false and third_party_silence=true; incomplete.
  • external_hosts crx JS contacts check.torproject.org, github.com, webbrowsertools.com — 3 distinct domains, 2 countries (CA, IN).
  • low_rating store Rating 3.4; community feedback below average for a security-category tool.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no trust anchors beyond the listing itself.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled proxy; core risk for this extension type.
  • storage low Stores local extension preferences; low standalone risk.
  • notifications low Can display desktop notifications; low risk without host access.
  • https://check.torproject.org/* medium Scoped host access to tor-check endpoint; matches stated function but adds network surface.

Pillar Scores

Permissions5.50
Reputation7.50
Network3.50
Webstore5.00
Maintenance3.50
Privacy6.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA a086e97c8dc3…
Force block — not fired
Score recovered no
Elapsed 22.8s