Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Browse with Onion

hfddekpiekhlkkgeaobcdkeonpkinipo
Risk Score
4.01
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 3,000
Rating 2.7
Last updated 2025-09-18 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer grephyr.prj@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows complete traffic interception/rerouting — core capability of a MITM attack if extension is malicious or compromised.
  • Install and uninstall URL hijacks present (target unknown) — possible phishing or tracking redirect.
  • Free-webmail developer (gmail.com) with no verified business identity; dev_email cluster shows 4 siblings under same email.
  • Privacy policy scoped but lacks data retention disclosure and third-party sharing is silenced.
  • Low rating (2.7) on a network-routing extension raises credibility concerns.

Evidence

  • proxy_permission manifest proxy declared; can intercept and redirect all browser HTTPS/HTTP traffic through arbitrary endpoints.
  • install_url_hijack crx install_url_hijack=true, target=null; onInstalled opens unknown 3rd-party URL.
  • uninstall_url_hijack crx uninstall_url_hijack=true, target=null; setUninstallURL points to unknown destination.
  • free_webmail_developer store Developer email grephyr.prj@gmail.com; no business domain; operator_cluster dev_email siblings=4.
  • low_rating store Rating 2.7; no rating count available; below-average trust signal for a proxy/routing extension.
  • no_csp manifest content_security_policy=null on MV3; no additional CSP hardening declared.
  • privacy_policy_retention_missing api Policy fetched, scoped to extension, no data collection — but retention=false and third_party_silence=true.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0, cve_findings_raw=[]; no malicious signals detected in scanned JS.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled or arbitrary proxy endpoints.
  • storage low Stores extension state locally; low standalone risk.
  • notifications low Can display desktop notifications; minimal abuse surface alone.
  • *://check.torproject.org/* low Narrow host permission scoped to Tor Project's check endpoint; matches stated function.

Pillar Scores

Permissions4.50
Reputation7.00
Network2.00
Webstore5.50
Maintenance1.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA 3d0868e50cf6…
Force block — not fired
Score recovered no
Elapsed 20.3s