Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Download manager integration checklist

ghkcpcihdonjljjddkmjccibagkjohpi
Risk Score
4.93
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 60,000
Rating 4.1
Last updated 2025-02-22 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Google brand impersonation: dev 'Merin' is unverified but uses Google's privacy policy and mentions Google brand.
  • Privacy policy is Google's generic account policy — not scoped to this extension; data_collection+third_party_sharing admitted.
  • content_scripts on <all_urls> injects JS into every site despite only 'storage' in permissions[].
  • Description promises download integration but lacks 'downloads' permission — mismatch raises shell-pattern concern.
  • 18 months since last update; stale at boundary; no email contact for accountability.

Evidence

  • brand_impersonation store brand_mention: Google mentioned, confirmed_owner=false, is_impersonation=true; dev is 'Merin' with no domain.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] injects into every page; no corresponding host_permissions declared.
  • description_permission_mismatch store Promises download functionality but 'downloads' permission absent; description_promise mismatch flagged.
  • dom_xss_sink crx innerHTML assigned from variable in popup.100f6462.js; no CSP to mitigate; DOM-XSS risk.
  • external_js_host crx js_external_hosts includes reactjs.org; extension references external domain in code.
  • stale_update store months_since_update=18; at the 12-24 month band boundary (+6.0 maintenance).
  • no_developer_email store developer_email is empty; no contact accountability; unverified publisher.

Permissions Breakdown

  • storage low Stores local data only; minimal risk in isolation.
  • content_scripts <all_urls> high Injects JS into every page; broad reach even without explicit host_permissions.

Pillar Scores

Permissions1.80
Reputation6.50
Network2.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:06
Listing SHA 24d955d06b94…
Force block — not fired
Score recovered no
Elapsed