Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AI assistant for Linkedin

hdopabkhobppbaaajnanhadcamfopobc
Risk Score
3.83
Risk Level: Low
Recommendation: 🚫 BLOCK
Category AI
Installs 1,000
Rating 4.3
Last updated 2026-05-13
Manifest version MV3
CSP present ❌ no
Developer yanis@ideta.io
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3 with no CSP — amplified XSS risk on LinkedIn pages.
  • Privacy policy is Google's generic account policy (scope_extension=false, admits data collection + 3rd-party sharing) — rates +10 under v3.5 rule D.
  • No CSP + dom_sink_innerhtml in contentScript running on linkedin.com creates live DOM-XSS attack surface.
  • brand_mention.is_impersonation=true for 'LinkedIn' without verified publisher status; LinkedIn is not confirmed owner.
  • function_constructor (new Function) in background.js and popup.js — dynamic code execution pathway without sandbox.

Evidence

  • cve_critical_underscore crx underscore@1.8.3 carries CVE-2021-23358 (critical, ACE); fixed_in 1.12.1. No CSP amplifies risk.
  • privacy_policy_generic_google store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_csp_dom_xss crx csp_present=false + 3 innerHTML-from-variable sinks in files running on linkedin.com.
  • brand_impersonation_linkedin store brand_mention.is_impersonation=true for LinkedIn; not verified_publisher, not confirmed_owner.
  • function_constructor_background crx new Function() in background.js and popup.js — dynamic code execution without CSP guard.
  • ai_extension_linkedin_content_script manifest AI extension with content_scripts on https://www.linkedin.com/* can read and modify all LinkedIn page content.
  • is_featured_by_google store Extension carries Featured badge — partial trust signal, but does not offset CVE and privacy deficiencies.
  • cve_high_underscore_dos crx CVE-2026-27601 (high) in underscore@1.8.3 — unlimited recursion DoS; fixed_in 1.13.8.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores extension preferences/state locally; limited blast radius.
  • *://*.ideta.io/* medium Allows content-script and fetch access to developer's own domain.
  • *://*.linkedin.com/* medium Content-script runs on LinkedIn pages; can read/modify LinkedIn DOM and data.

Pillar Scores

Permissions2.30
Reputation6.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:17
Listing SHA c5a5f1013096…
Force block — not fired
Score recovered no
Elapsed 532.0s