Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Celestial horizon above the storm

hbhamhdmcofpadbpdkpdlmkgheonnigl
Risk Score
3.63
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category NewTab
Installs 8
Rating
Last updated 2026-05-14 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijack both fire to gameograf.com with UTM tracking — monetization shell pattern.
  • NewTab override with search permission is a primary ad-monetization vector.
  • Two innerHTML DOM-XSS sinks (popup.js, calendar.js) without CSP protection.
  • Developer name (Dekuy.com) mismatches email domain (gameograf.com) — inconsistent identity.
  • No CSP declared on MV3; innerHTML sinks elevate XSS risk if remote content is ever injected.

Evidence

  • install_url_hijack + uninstall_url_hijack manifest Both onInstalled and uninstall callbacks redirect to gameograf.com with UTM params — classic monetization shell.
  • chrome_url_overrides.newtab manifest Extension replaces new tab page; combined with search permission indicates ad/search monetization intent.
  • dom_sink_innerhtml_userctrl x2 crx innerHTML sinks in popup.js and calendar.js; no CSP present to mitigate DOM-XSS.
  • developer identity mismatch store Developer name is Dekuy.com but email is support@gameograf.com — two different brand namespaces.
  • privacy_policy_classification api Policy fetched, scoped, discloses collection, retention, and third-party sharing — adequate.
  • no_cve_findings crx jquery 3.7.1 bundled — no known CVEs at this version.
  • operator_cluster.sibling_count=0 api No sibling extensions detected under same fingerprint; isolated deployment.
  • install_count=8 store Extremely low installs (8); tail-attack-surface flag not triggered but anomalous for a published extension.

Permissions Breakdown

  • search medium Can manipulate search queries/provider; common in NewTab monetization shells.
  • host_permissions: https://api.gameograf.com/* medium Scoped to developer's own API domain; but used for install/uninstall tracking.
  • chrome_url_overrides: newtab medium Replaces new tab page — primary monetization vector for this category.

Pillar Scores

Permissions3.00
Reputation5.50
Network2.00
Webstore7.00
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:18
Listing SHA 1b96f02c09f1…
Force block — not fired
Score recovered no
Elapsed