Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Grok AI

hafhkoalnlpoifpidohfjlmeemfifndi
Risk Score
5.30
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 20,000
Rating 4.7
Last updated 2025-10-30 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer joldeveloply@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail dev (joldeveloply@gmail.com) with no developer name — unverifiable operator identity impersonating 'Grok AI' brand.
  • Privacy policy is Google's generic account policy — no scope to this extension; policy admits data collection and 3rd-party sharing.
  • Uninstall and install URL hijacks declared — classic traffic-monetization shell pattern.
  • 6 external JS hosts on easytool.dev subdomain (chatgpt-5, deepseek-ai, gemini-2, grok-3, grok-ai, perplexity-ai) loaded remotely — supply-chain risk.
  • No CSP and DOM-XSS innerHTML sink in iframe-service JS — remote JS hosts can inject arbitrary content.

Evidence

  • free_webmail_dev_no_name store Developer email joldeveloply@gmail.com; developer_name is empty. No verifiable business identity.
  • install_uninstall_url_hijack crx Both uninstall_url_hijack and install_url_hijack are true — monetization shell fingerprint.
  • external_js_hosts crx 6 easytool.dev subdomains loaded as external JS: chatgpt-5, deepseek-ai, gemini-2, grok-3, grok-ai, perplexity-ai.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; collects+shares data.
  • no_csp_dom_xss_sink crx csp_present=false AND dom_sink_innerhtml_userctrl in iframe-service-D2VojyOp.js — XSS risk amplified.
  • is_featured_by_google store Extension carries Google Featured badge, partially offsetting reputation concern.
  • ai_extension_multi_provider_hosts crx Extension hosts content from 6 AI-brand subdomains under single easytool.dev operator — aggregator shell pattern.
  • manifest_localized_name_desc crx manifest_name=__MSG_appName__ and manifest_description=__MSG_shortDesc__ — store name relies entirely on locale strings.

Permissions Breakdown

  • storage low Local key-value storage only; no cross-origin data exfil by itself.
  • sidePanel low Opens a side panel UI; no sensitive data access on its own.

Pillar Scores

Permissions0.60
Reputation8.00
Network3.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:42
Listing SHA 50f3b4c46a5a…
Force block — not fired
Score recovered no
Elapsed