Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Writer

hngnkmianenpifegfoggnkamjnffiobn
Risk Score
5.76
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 70,000
Rating 4.4
Last updated 2026-05-29 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer waseem@writer.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: arbitrary code execution); no CSP amplifies exploitability.
  • Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true — admits broad data sharing without scoping to this extension.
  • cookies + scripting + broad host_permissions (<all_urls>) allows reading auth cookies and injecting JS on every site.
  • new Function() constructor used in 4 JS files — dynamic code execution risk, especially without CSP.
  • AI extension processing page content across all URLs; 6 distinct external JS hosts contacted at runtime.

Evidence

  • cve_critical_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed in 1.12.1. No CSP present — v2 amplifier applies.
  • privacy_policy_scope_mismatch store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.0 privacy.
  • broad_host_cookies_scripting manifest cookies + scripting + http://*/ + https://*/ — can exfiltrate auth cookies from any site.
  • function_constructor_no_csp crx new Function() in 4 files; csp_present=false — dynamic code execution without CSP mitigation.
  • ai_extension_page_content store Described as generative AI; content_scripts on <all_urls> — processes content on every visited page.
  • no_developer_name store developer_name is empty string; dev email waseem@writer.com on writer.com domain which resolves.
  • 6_external_js_hosts crx Contacts api.statsigcdn.com, featureassets.org, github.com, prodregistryv2.org, reactjs.org, support.writer.com.
  • featured_by_google store is_featured_by_google=true; not verified_publisher. Partial trust signal, no verified discount.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Can enumerate open tabs and their URLs.
  • cookies high Read/write cookies across origins; paired with broad host access amplifies risk.
  • storage low Local extension storage; low risk alone.
  • scripting high Can inject JS into any page given broad host_permissions.
  • sidePanel low UI surface only; low risk.
  • http://*/ high Broad host access over all HTTP origins.
  • https://*/ high Broad host access over all HTTPS origins; cookies+scripting+<all_urls> combo ×1.2.

Pillar Scores

Permissions7.50
Reputation4.00
Network5.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA f6161908042f…
Force block — not fired
Score recovered no
Elapsed 33.5s