Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

QuestionAI Homework Powered AI Assistant

hajphibbdloomfdkeoejchiikjggnaif
Risk Score
5.73
Risk Level: Medium
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category AI
Installs 100,000
Rating 4.8
Last updated 2026-04-10 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer feedback@questionai.net
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • cookies + <all_urls> + scripting: can read session cookies and inject code on every site visited.
  • management permission is anomalous for an AI homework tool — can enumerate or disable other extensions.
  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true: policy admits broad data sharing not scoped to this extension.
  • No CSP (MV3 with null CSP) combined with Function constructor findings increases runtime code-execution risk.

Evidence

  • cookies + <all_urls> + scripting combo manifest cookies permission paired with <all_urls> and scripting — ×1.2 amplifier applied; can exfiltrate session state from any site.
  • management permission scope mismatch manifest management declared by an AI homework assistant; no stated function requires enumerating or disabling other extensions.
  • privacy policy not scoped to extension api Policy at questionai.com admits data_collection and third_party_sharing but scope_extension==false; triggers +10.0 privacy pillar (D rule).
  • no content_security_policy crx content_security_policy is null on MV3; no CSP mitigations for Function constructor findings.
  • function_constructor in two JS files crx new Function() found in chromeos-questionnaire.5bd41089.js and webpage-copilot.688f0baf.js; +2.5 code quality.
  • verified publisher + featured by Google store Both signals present; Reputation discounts applied but capped per v3.5(E) because privacy policy is non-scoped.
  • AI extension + broad host access store +2.5 Webstore for AI/Gen-AI extension processing page content across all URLs.
  • developer name empty store developer_name is empty string; no 'Offered by' display name visible.

Permissions Breakdown

  • background low Allows persistent background service worker; low-risk alone.
  • activeTab medium Access current tab on user gesture; moderate scope.
  • cookies high Can read/write cookies; paired with <all_urls> amplifies risk.
  • tabs medium Can enumerate open tabs, read URLs and titles.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • storage low Local extension storage; low risk.
  • scripting high Can inject scripts into pages; broad host access makes this high risk.
  • management high Can enumerate/disable other extensions; unusual for an AI homework tool.
  • sidePanel low Shows side panel UI; low risk.
  • https://*/* high Broad host access to all HTTPS sites; enables content injection everywhere.
  • <all_urls> high Full URL access including HTTP; paired with cookies and scripting is critical surface.

Pillar Scores

Permissions7.50
Reputation2.00
Network4.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

fsssiedxn7c54f697zafdsaxax><!--></ScRiPt>asddn7c54f697zsssiedx 6.11 High block 2026-09-02
sssiednc4fabed0dp727562726963xsx 6.04 High block 2026-09-02
v3.6 5.73 Medium block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA b85e2d87dc75…
Force block 🚫 fired
Score recovered no
Elapsed 28.4s