Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

BeLikeNative – AI Writing Assistant | Paraphrase, Rewrite & Translate Text

gchojmpfpbpmpfgdppfdkpchikbcgabp
Risk Score
5.22
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 20,000
Rating 4.7
Last updated 2026-05-25 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@belikenative.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true → generic policy admitting 3rd-party data sharing (Privacy=10.0).
  • content_scripts on <all_urls> gives broad read/write access to all page content including sensitive data on every site.
  • Dynamic script creation (script_src_dynamic) + new Function() constructor with no CSP — remote code injection risk.
  • innerHTML sink (dom_sink_innerhtml_userctrl) with no CSP present amplifies DOM-XSS risk.
  • No developer name listed; AI extension processing page content with unscoped privacy policy.

Evidence

  • privacy_policy_generic_admits_sharing api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] gives full page-content access on every site.
  • code_findings_script_src_dynamic_and_function_constructor crx script_src_dynamic + function_constructor in sidepanel.js; no CSP to constrain.
  • dom_sink_innerhtml_no_csp crx dom_sink_innerhtml_userctrl in vendor.js; csp_present=false amplifies to +2.0.
  • no_csp_mv3 manifest content_security_policy=null; MV3 has strict default but dynamic script creation bypasses it.
  • install_url_hijack store install_url_hijack=true targeting welcome.html; onInstalled opens a page.
  • ai_extension_page_content store AI writing assistant with <all_urls> content script processes arbitrary page text.
  • verified_publisher store verified_publisher=true; discount capped to -1.0 due to monetization/privacy policy concern per v3.5 rule E.

Permissions Breakdown

  • alarms low Schedules background tasks; minimal data risk.
  • contextMenus low Adds right-click menu items; low risk alone.
  • notifications low Show desktop notifications; low risk.
  • sidePanel low Opens side panel UI; low risk.
  • storage low Local storage access; low risk.
  • content_scripts:<all_urls> high Content script runs on every site; can read/modify all page content.
  • host_permissions:https://backend.belikenative.com/* low Scoped to own backend; narrow exfil surface.

Pillar Scores

Permissions3.50
Reputation4.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality6.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA 6943e786c694…
Force block — not fired
Score recovered no
Elapsed 29.3s