Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CommenTron — AI Booster for LinkedIn

hdappgahcgpifoabanfifjicfllpokgo
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 3,000
Rating 4.7
Last updated 2026-07-30 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@rocket-pod.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: LinkedIn brand referenced without confirmed ownership; is_impersonation=true.
  • AI extension processes LinkedIn page content with scripting + host access — high data-exfil surface.
  • Two innerHTML DOM-XSS sinks found in content and popup scripts; no CSP to mitigate.
  • Privacy policy discloses third-party data sharing scoped to this extension — data leaves the device.
  • No CSP present (MV3 default applies) combined with DOM sinks raises XSS exploitability.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; LinkedIn brand used, confirmed_owner=false, developer domain rocket-pod.com.
  • ai_page_content_processing manifest AI extension with scripting + content_scripts on linkedin.com; processes LinkedIn post content for AI comment generation.
  • dom_xss_sinks crx Two dom_sink_innerhtml_userctrl findings in contents.e7997a5d.js and popup.68feda32.js; no CSP present.
  • no_csp crx content_security_policy is null; MV3 default applies but dom_sink findings increase XSS risk without explicit hardening.
  • privacy_third_party_sharing api Privacy policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.
  • featured_by_google store is_featured_by_google=true; partial trust signal, offsets reputation penalty partially.
  • narrow_host_scope manifest host_permissions and content_scripts limited to https://www.linkedin.com/*; no broad cross-site access.
  • operator_cluster_clean api sibling_count=0; no known sibling extensions under same fingerprint. bad_host_hits, affiliate_hits, monetization_hits all empty.

Permissions Breakdown

  • storage low Local data persistence; no cross-origin access implied.
  • scripting medium Allows programmatic script injection; scoped to linkedin.com via host_permissions.
  • https://www.linkedin.com/* medium Host access scoped to single domain; sufficient for stated function but enables DOM read/write.

Pillar Scores

Permissions2.00
Reputation5.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy1.00
Code Quality4.00
CVE Exposure0.00

Scoring History

sssiedn9dd01e40dp727562726963xsx 2.04 Low review 2026-09-12
v3.6 4.07 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA e9d9a09ca0c0…
Force block — not fired
Score recovered no
Elapsed 24.4s