Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Torii Image Translator — AI Manga Translator, Manhwa Translator ...

gkdekajjngdkocgiealohleibhdjhoed
Risk Score
3.07
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category TranslationTool
Installs 10,000
Rating 4.3
Last updated 2026-07-31 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@toriitranslate.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • declarativeNetRequestWithHostAccess + <all_urls> allows network-level interception on every site visited.
  • External JS hosts include raw.github.com and stuartk.com — non-dev-controlled domains could serve updated code.
  • function_constructor (new Function()) in zip.js enables dynamic code execution.
  • No CSP declared (MV3 default helps but no explicit restriction); dom_sink_innerhtml_userctrl present.
  • No developer name listed in store; AI translation of page content processed via dev API.

Evidence

  • declarativeNetRequestWithHostAccess + <all_urls> manifest HIGH permission paired with broad host access; can intercept requests sitewide.
  • external_hosts_non_dev crx raw.github.com, stuartk.com, stuk.github.io contacted — third-party non-dev-controlled JS endpoints.
  • verified_publisher + featured store Extension carries both verified publisher and Google featured badges; reputation discounts applied.
  • privacy_policy_adequate api Policy scoped to extension, discloses data collection, retention, and third-party sharing.
  • function_constructor crx new Function() in scripts/zip.js enables dynamic code eval; likely from bundled zip library.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in content.js; no CSP to mitigate DOM-XSS risk.
  • no_developer_name store developer_name field empty in listing; minor identity gap despite verified publisher badge.
  • geo_diversity_3_countries api JS hosts span CA, DE, US — 3 countries, below +1.5 threshold of 4.

Permissions Breakdown

  • activeTab low Grants access to the currently active tab only on user action.
  • storage low Local data persistence; low risk in isolation.
  • contextMenus low Adds right-click menu entries; standard UX pattern.
  • declarativeNetRequestWithHostAccess high Can intercept/block/redirect network requests on all URLs.
  • unlimitedStorage low Storage quota only; no data exfil risk on its own.
  • <all_urls> (host_permissions) high Content scripts injected into every site; broad data access.

Pillar Scores

Permissions5.50
Reputation2.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy0.00
Code Quality3.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:54
Listing SHA 782ea936019d…
Force block — not fired
Score recovered no
Elapsed