Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Gemini Chat Sidebar

hcclofdokohcpnenkiamgnageeaclfce
Risk Score
5.84
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 10,000
Rating 4.3
Last updated 2026-05-21 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer dev@igemini.vip
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; collects and shares data with third parties.
  • desktopCapture + scripting + <all_urls> gives broad screen and page access on every site visited.
  • No CSP present (MV3); three innerHTML sinks across content/sidebar scripts elevate DOM-XSS risk.
  • Developer identity is minimal (single name 'Garcia', custom .vip domain, unverified publisher).
  • AI extension processes page content on all URLs with screen capture capability — high exfil surface.

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; data_collection+third_party_sharing=true.
  • desktopCapture_permission manifest desktopCapture declared alongside scripting and <all_urls> — allows screen capture on any page.
  • no_csp crx content_security_policy is null; no CSP protection for MV3 extension with DOM sinks.
  • dom_xss_sinks crx Three files contain innerHTML assignments from variables with no CSP guard — DOM-XSS risk.
  • unverified_publisher store verified_publisher=false, is_featured_by_google=false; developer is 'Garcia' at igemini.vip.
  • ai_page_content_access manifest AI category extension with content_scripts on <all_urls> and desktopCapture — broad data access.
  • ko_fi_external_host crx js_external_hosts includes ko-fi.com and storage.ko-fi.com — donation/monetization widget bundled.
  • brand_mention_confirmed_owner store brand_mention.is_impersonation=false, confirmed_owner=true for 'gemini' brand reference.

Permissions Breakdown

  • storage low Standard key-value storage, low risk.
  • unlimitedStorage low Allows large storage quota; minor risk.
  • sidePanel low Opens a side panel UI; low direct risk.
  • activeTab medium Grants access to the current tab on activation.
  • scripting high Allows programmatic JS injection into pages.
  • downloads medium Can initiate and manage file downloads.
  • desktopCapture high Can capture screen content — significant privacy risk.
  • <all_urls> (host) high Content scripts run on every page; broad reach amplifies scripting risk.

Pillar Scores

Permissions7.50
Reputation5.50
Network4.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA b266cb09c5e7…
Force block — not fired
Score recovered no
Elapsed 27.5s