Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AI Sidebar

gghdfkafnhfpaooiolhncejnlgglhkhe
Risk Score
4.59
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 50,000
Rating 4.2
Last updated 2026-06-26 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer ai.technetic@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail developer (gmail) with no verified identity or business website — high accountability gap.
  • Privacy policy is Google's generic account policy — does not scope to this extension; admits data collection and 3rd-party sharing.
  • scripting + <all_urls> + content_scripts on all URLs gives full page-content access across every site visited.
  • Install-URL hijack opens 3rd-party page on install; no CSP; 8 external JS hosts including 'pay.your-domain.com'.
  • AI extension processes page content sent to platform.ai-sidebar.app with no scoped privacy disclosure.

Evidence

  • free_webmail_developer store Developer email ai.technetic@gmail.com; no developer name; no business website — identity unverifiable.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
  • install_url_hijack manifest install_url_hijack=true opens 3rd-party URL on install.
  • broad_host_plus_scripting manifest host_permissions=<all_urls> + scripting + content_scripts on <all_urls> — can read/modify every page.
  • external_js_hosts crx 8 external hosts including pay.your-domain.com and platform.ai-sidebar.app; CSP absent on MV3 extension.
  • ai_page_content_processing store AI Sidebar category processes active-page content; data sent to platform.ai-sidebar.app with no scoped privacy policy.
  • function_constructor_finding crx new Function() in pdf-hY71vyYA.js; dom_sink_innerhtml_userctrl in App-D7FTCMyE.js — XSS/eval risk.
  • no_developer_name_featured store No developer name listed despite is_featured_by_google=true; email is free webmail.

Permissions Breakdown

  • sidePanel low UI panel — low direct data risk.
  • storage low Local storage for settings.
  • unlimitedStorage low Extended local storage quota only.
  • activeTab medium Access to current tab content on user action.
  • scripting high Can inject scripts into pages; combined with <all_urls> enables broad content manipulation.
  • tabs medium Read URLs/titles of all open tabs.
  • contextMenus low Adds right-click menu items.
  • offscreen low Background DOM processing; low direct risk.
  • <all_urls> (host) high Combined with scripting, enables full page content access across every site visited.

Pillar Scores

Permissions7.00
Reputation7.00
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:07
Listing SHA 7ea147b57154…
Force block — not fired
Score recovered no
Elapsed