Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Slack Deleter

fojaboengkcdjplnfcocfnchkjdikfei
Risk Score
6.36
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 3,000
Rating 2.1
Last updated 2022-12-21 (42 months ago)
Manifest version MV3
CSP present ✅ yes
Developer hhhust@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension stale >36 months (42mo) — abandoned, unpatched, high takeover risk.
  • Brand impersonation of Slack by unverified free-webmail dev (hhhust@gmail.com).
  • Privacy policy is generic Google account policy — does not scope to this extension at all.
  • Content script runs on all *.slack.com pages; exfiltrates potential workspace tokens to slackext.com.
  • DOM innerHTML sink in bundle creates XSS risk if slackext.com response is ever compromised.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'slack'; confirmed_owner=false; dev is free-webmail gmail.
  • stale_extension store Last updated Dec 21 2022; 42 months since update — zombie-tier abandonment.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • third_party_host_outbound manifest host_permissions and CSP connect-src include https://slackext.com — unknown third-party server.
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in slackdeleter.bundle.js; CSP present but style-src allows unsafe-inline.
  • free_webmail_dev_no_name store developer_name empty; developer_email hhhust@gmail.com; no business domain.
  • low_rating store Rating 2.1 — below 3.0 threshold indicating user dissatisfaction.
  • telemetry_hit crx CSP connect-src includes ssl.google-analytics.com; monetization_hits confirm analytics beacon.

Permissions Breakdown

  • storage low Local key-value storage; no cross-site exposure.
  • activeTab low Transient access to current tab on user gesture only.
  • host:https://slackext.com/* medium Permits outbound requests to a third-party server not controlled by Slack.
  • content_scripts:https://*.slack.com/* medium Script runs in all Slack pages; can read workspace messages and tokens.

Pillar Scores

Permissions2.30
Reputation8.50
Network2.50
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA 6782daf2a43b…
Force block — not fired
Score recovered no
Elapsed 22.3s