Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Annotate the Web

hkdbcemiphlcpmcphjgfaepgciimcoef
Risk Score
3.27
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Screenshot
Installs
Rating 4.5
Last updated 2025-10-23 (8 months ago)
Manifest version MV3
CSP present ✅ yes
Developer hpleitez@ps109x.org
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • 7 moderate CVEs in bundled jquery@3.3.1 and jquery-ui@1.12.1 (multiple XSS vectors, all unpatched).
  • <all_urls> host permission + scripting enables content injection on every site visited.
  • Privacy policy hosted on Google Sites, no data retention disclosed, third-party sharing silence.
  • Doubleclick/Google Analytics telemetry endpoints in CSP; doubleclick is ad-tier beyond pure analytics.
  • Description promises 'recording' but lacks tabCapture/desktopCapture — minor permission mismatch.

Evidence

  • multiple_moderate_cves crx 7 moderate CVEs across jquery@3.3.1 (3) and jquery-ui@1.12.1 (4); all below fixed_in versions.
  • host_permissions_all_urls manifest <all_urls> paired with scripting and content_scripts; broad page access for annotation tool.
  • monetization_hits crx stats.g.doubleclick.net in js_external_hosts — ad-tech tier beyond analytics telemetry.
  • privacy_policy_google_sites store Policy on sites.google.com; scope_extension=true but retention=false, third_party_silence=true.
  • description_promise_mismatch store Description says 'save as screenshot' but also implies recording without tabCapture permission.
  • no_obfuscation_clean_code crx obfuscation_score=0.0, code_findings_raw empty; code itself is clean.
  • csp_present_mv3 manifest script-src 'self'; object-src 'self' — restrictive CSP, MV3. No unsafe-eval/inline.
  • developer_domain_resolves api ps109x.org resolves, looks_throwaway=false, no bad_host_hits, sibling_count=0.

CVE Exposures (7)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.12.1 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2021-41183 jquery-ui@1.12.1 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • activeTab low Scoped to user-initiated interactions only; lower risk than broad host access.
  • storage low Local data persistence; no exfiltration risk on its own.
  • scripting medium Can inject scripts into pages; elevated when combined with <all_urls> host permission.
  • <all_urls> (host_permission) high Grants access to every site the user visits; broad attack surface for annotation/screenshot use.

Pillar Scores

Permissions3.50
Reputation5.00
Network3.50
Webstore3.00
Maintenance1.50
Privacy2.00
Code Quality0.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA 2422bd4c584e…
Force block — not fired
Score recovered no
Elapsed 29.8s