Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ask Steve: Time-Saving AI Agents For Your Browser

gldebcpkoojijledacjeboaehblhfbjg
Risk Score
4.82
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 3,000
Rating 4.8
Last updated 2026-04-28 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@asksteve.to
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + scripting + <all_urls>: extension can read/write cookies and inject code on every site the user visits
  • 16 innerHTML DOM-XSS sinks across core scripts with no CSP — severe risk of content injection into extension UI
  • No CSP (MV3 content_security_policy null) with function_constructor usage in bundled sweetalert2 and service-worker
  • AI extension processes page content and contacts external hosts including jsdelivr CDN and Google services
  • No developer name listed; AI agent category with broad host access warrants manual review before enterprise deployment

Evidence

  • broad_host_access_cookies_scripting manifest cookies + scripting + http://*/* + https://*/* — can read all cookies and inject scripts on any site
  • no_csp crx content_security_policy is null; MV3 default applies but no explicit hardening
  • dom_sink_innerHTML_pervasive crx 14 innerHTML DOM-XSS sinks in scripts/asksteve.js, backup.js, sidepanel.js, service-worker.js, and 10 others
  • function_constructor_in_bundled_lib crx new Function() in sweetalert2.min.js and service-worker.js; no CSP amplifies risk
  • ai_extension_page_content store AI agent category; processes page content via content_scripts on all URLs
  • external_cdn_host crx js_external_hosts includes www.jsdelivr.com — external CDN contact from extension code
  • no_developer_name store developer_name is empty string; only email support@asksteve.to available
  • featured_by_google store is_featured_by_google=true provides moderate reputation signal; not verified publisher

Permissions Breakdown

  • storage low Standard local data storage.
  • sidePanel low UI panel access, low direct risk.
  • tabs medium Access to tab URLs, titles, navigation — broad browsing visibility.
  • scripting high Paired with <all_urls> host permissions; can inject code into any page.
  • unlimitedStorage low Extended local storage quota only.
  • contextMenus low Adds right-click menu items, minimal risk.
  • offscreen medium Off-screen document can process content outside normal visibility.
  • cookies high Combined with broad host access enables reading/writing cookies on any site.
  • declarativeNetRequest medium Can modify/block network requests declaratively.
  • http://*/* high Full host access to all HTTP sites.
  • https://*/* high Full host access to all HTTPS sites.

Pillar Scores

Permissions7.50
Reputation5.50
Network5.50
Webstore4.50
Maintenance0.00
Privacy1.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA c23bca13d4b9…
Force block — not fired
Score recovered no
Elapsed 29.5s