Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Toby: Tab Management Tool

hddnkoipeenegfoeaoibdmnaalmgkpip
Risk Score
4.51
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 300,000
Rating 4.2
Last updated 2026-06-03 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer hello@gettoby.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension (generic corporate policy).
  • NewTab override with 300K installs — high-engagement surface for potential monetization or data capture.
  • declarativeNetRequestWithHostAccess can intercept/modify network requests; elevated capability for a tab manager.
  • tabs permission exposes URLs/titles of all open tabs; combined with analytics endpoints (Amplitude, Mixpanel) raises tracking concern.
  • Three innerHTML DOM-XSS sinks in content scripts and background; CSP style-src uses 'unsafe-inline' and wildcard.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = toby.html; replaces new-tab page for all 300K users.
  • privacy_policy_scope_mismatch api Policy fetched; data_collection=true, third_party_sharing=true, scope_extension=false — generic policy, not extension-scoped.
  • analytics_endpoints crx JS contacts api.amplitude.com and api.mixpanel.com; telemetry sent alongside tabs metadata.
  • dom_xss_sinks crx 3 innerHTML assignments from variables found in background.js, Note chunk, and content-script inject-public.js.
  • csp_style_wildcard_unsafe_inline manifest style-src includes 'unsafe-inline' and '*'; weakens CSP protections against style injection.
  • declarativeNetRequestWithHostAccess manifest High-capability permission to intercept requests; only scoped to *.gettoby.com but still elevated.
  • featured_by_google store Extension is featured by Google — partial trust signal; no verified publisher badge.
  • no_developer_name store developer_name is empty string; only email hello@gettoby.com available.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; limited surface.
  • unlimitedStorage low Allows large local data storage; no exfil risk alone.
  • storage low Standard sync/local storage; expected for tab manager.
  • tabs medium Can read tab URLs/titles across all tabs — broad metadata access.
  • declarativeNetRequestWithHostAccess high Can intercept/block network requests; paired with host permissions.
  • chrome_url_overrides.newtab medium Replaces new-tab page; high-engagement surface, monetization risk.
  • host_permissions: https://*.gettoby.com/ low Scoped to developer's own domain; low third-party risk.

Pillar Scores

Permissions5.50
Reputation4.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality1.50
CVE Exposure0.00

Scoring History

fsssiedxn3098b1a7zan3098b1a7zsssiedx 4.35 Medium review 2026-09-10
fsssiedxn7d207a5dza"n7d207a5dzsssiedx 4.05 Medium review 2026-09-10
fsssiedxnd9aba880za 4.16 Medium review 2026-09-10
sssiednb176aaa3dp727562726963xsx 4.32 Medium review 2026-09-10
sssiedn6e5843eddp727562726963xsx 4.37 Medium review 2026-09-09
fsssiedxn631d8d59zan631d8d59zsssiedx 4.14 Medium review 2026-09-03
fsssiedxn70e964deza'n70e964dezsssiedx 4.44 Medium review 2026-09-03
fsssiedxn9b1c436aza"n9b1c436azsssiedx 4.22 Medium review 2026-09-03
sssiednac25ed38dp727562726963xsx 4.08 Medium review 2026-09-03
fsssiedxn591fddc3za"n591fddc3zsssiedx 4.27 Medium review 2026-09-02
sssiedn3875a014dp727562726963xsx 4.04 Medium review 2026-09-02
fsssiedxnddd64236zafdsaxax><!--></ScRiPt>asddnddd64236zsssiedx 4.26 Medium review 2026-08-30
fsssiedxne87ff5e8za 4.26 Medium review 2026-08-30
sssiedn3e356232dp727562726963xsx 4.19 Medium review 2026-08-30
fsssiedxasssiedx 4.12 Medium review 2026-08-08
fsssiedxa 4.01 Medium review 2026-08-08
sssieddrubricxsx 4.28 Medium review 2026-08-08
v3.6 4.51 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA 57c6dfefea58…
Force block — not fired
Score recovered no
Elapsed 26.9s