Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AI Customer Service Assistant

hadgldgnglbhjbcoaaihkifphdhfjpbg
Risk Score
3.61
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 9
Rating 5.0
Last updated 2026-06-25 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer yuzeyuan125@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returns fetch error — policy is effectively unavailable; data handling unknown.
  • Developer uses free-webmail (gmail) with no verified business identity.
  • innerHTML DOM sink in sidepanel.js could enable XSS if AI API response is attacker-influenced.
  • Tiny install base (9) makes independent trust validation impossible.
  • Privacy policy domain (crossplanetai.com) is unverified; developer_domain_info is null.

Evidence

  • privacy_policy_fetch_failed api https://crossplanetai.com/privacy returned HTTPError; policy content unverifiable — scored +10.0 privacy.
  • free_webmail_developer store Developer email yuzeyuan125@gmail.com; no verified business; no publisher badge — reputation +1.5.
  • dom_sink_innerhtml_userctrl crx sidepanel.js sets body.innerHTML from template variable containing AI response data — DOM-XSS risk.
  • narrow_permissions manifest Only sidePanel, storage, contextMenus, activeTab + single host permission api.deepseek.com; low capability surface.
  • csp_present_mv3 manifest CSP script-src 'self'; object-src 'self' — strict; no remote script loading allowed.
  • no_cve_findings crx No CVEs detected in bundled JS libraries; cve_findings_raw empty.
  • low_install_count store Only 9 installs; no community validation possible.
  • no_operator_siblings api operator_cluster sibling_count=0; no cluster risk detected.

Permissions Breakdown

  • sidePanel low Opens a side panel UI; no data access.
  • storage low Local extension storage only.
  • contextMenus low Adds right-click menu items; low risk.
  • activeTab low Temporary access to current tab on user action only.
  • https://api.deepseek.com/* low Narrow host permission scoped to declared AI backend only.

Pillar Scores

Permissions1.20
Reputation6.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:41
Listing SHA 94af0636ae18…
Force block — not fired
Score recovered no
Elapsed