Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screenshot YouTube

gjoijpfmdhbjkkgnmahganhoinjjpohk
Risk Score
4.17
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 500,000
Rating 4.4
Last updated 2024-12-26 (20 months ago)
Manifest version MV3
CSP present ❌ no
Developer zdenek.gromnica@futuremillennium.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (v3.5-D → +10.0 privacy pillar).
  • Brand impersonation: 'YouTube' in name, developer is not YouTube/Google, and not verified publisher.
  • Description promises recording but lacks tabCapture/desktopCapture — permission/function mismatch.
  • No developer display name listed in store; reduces accountability.
  • MV3 but no CSP declared; +2.0 network behavior per v2 calibration fix (b).

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google account policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true, brands=[youtube], confirmed_owner=false, not verified_publisher, not featured → +2.0 reputation.
  • description_mismatch store Promises recording but lacks tabCapture/desktopCapture permission → +2.0 webstore.
  • no_developer_name store developer_name is empty string → +1.0 reputation.
  • no_csp_mv3 manifest content_security_policy=null on MV3 extension → +2.0 network behavior per v2 fix (b).
  • maintenance_stale store months_since_update=18, in 12-24mo band → +6.0 maintenance; reduced by -1.0 for changelog discount not applicable (no evidence).
  • featured_by_google store is_featured_by_google=true → -2.0 reputation discount applied.
  • install_count store 500,000 installs → +1.0 (>10K) +1.0 (>100K) webstore; category Screenshot gets justified-broad discount not applicable (no broad host).

Permissions Breakdown

  • storage low Stores user settings locally; minimal risk.
  • content_scripts:https://www.youtube.com/* medium Injects scripts into YouTube pages; scoped to single domain.

Pillar Scores

Permissions1.30
Reputation6.00
Network2.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

fsssiedxa xx psssiedx 4.26 Medium review 2026-08-22
sssieddrubricxsx 4.59 Medium review 2026-08-22
v3.6 4.17 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 723c987f8c8c…
Force block — not fired
Score recovered no
Elapsed 20.6s