Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

J2TEAM Security

hmlcjjclebjnfohgmgikjfnbmfkigocc
Risk Score
3.76
Risk Level: Low
Recommendation: ✅ ALLOW
Category Security
Installs 300,000
Rating 4.9
Last updated 2026-05-23 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer junookyo@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no listed developer name; accountability gap for 300K-install security tool.
  • cookies + broad host permissions (<all_urls>): can read session cookies from any site visited.
  • webRequest + scripting + broad hosts: full traffic intercept and script injection capability across all sites.
  • install_url_hijack and uninstall_url_hijack flags detected; potential for redirect abuse on install/remove.
  • 12 external JS hosts including ad/social domains (facebook, adsmanager.facebook.com); geo diversity spans 4 countries.

Evidence

  • free_webmail_dev store developer_email=junookyo@gmail.com; no developer_name; gmail raises accountability concern for 300K users.
  • verified_publisher+featured store verified_publisher=true and is_featured_by_google=true; discounts reputation risk partially.
  • install_url_hijack+uninstall_url_hijack crx install_url_hijack=true, uninstall_url_hijack=true (targets null); pattern warrants review.
  • broad_host_plus_cookies manifest cookies + http://*/* + https://*/* + webRequest: can read/write cookies and intercept requests site-wide.
  • external_hosts_social_ad crx js_external_hosts includes adsmanager.facebook.com, connect.facebook.net, www.facebook.com among 12 hosts.
  • geo_diversity_4_countries api JS hosts span CA, IN, SG, US — 4 countries; +1.5 network penalty applies.
  • privacy_policy_adequate api Policy fetched, scoped, data_collection+retention+third_party_sharing all disclosed; third_party_silence=false.
  • dom_xss_sinks crx 2 innerHTML-from-variable findings in bundled chunks; CSP present (script-src self) limits exploitation.

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; moderate sensitivity for a security tool.
  • notifications low Display alerts; low abuse potential.
  • contextMenus low Adds right-click menu items; low risk.
  • cookies high Read/write cookies across all origins; combined with broad host access = high risk.
  • storage low Local extension data only.
  • unlimitedStorage low Extended local quota; low risk alone.
  • webRequest high Observe/intercept all HTTP requests; core to security tools but high capability.
  • alarms low Scheduled tasks; low risk.
  • scripting high Programmatic script injection into pages; combined with broad hosts = high risk.
  • declarativeNetRequest medium Declarative request blocking; less powerful than webRequestBlocking.
  • sidePanel low UI panel only; low risk.
  • http://*/* high Broad host access to all HTTP sites.
  • https://*/* high Broad host access to all HTTPS sites.

Pillar Scores

Permissions6.50
Reputation3.50
Network3.50
Webstore4.00
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Scoring History

v3.6 3.76 Low allow 2026-06-16
v3.4-rev 3.05 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA e165dad35f60…
Force block — not fired
Score recovered no
Elapsed 31.4s