Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Allow CSP: Content-Security-Policy

hnojoemndpdjofcdaonbefcfecpjfflh
Risk Score
5.33
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 10,000
Rating 4.0
Last updated 2025-09-10 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer mujo.hydrov@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is generic Google account policy (scope_extension==false, data_collection==true, third_party_sharing==true) — worst-case Privacy score.
  • Install and uninstall URL hijack flags set — extension opens/redirects on install/uninstall events.
  • Developer uses free Gmail account with no verifiable business identity; featured badge partially mitigates.
  • <all_urls> host permission paired with declarativeNetRequest allows CSP stripping on every site, significant attack surface.
  • External JS host webbrowsertools.com detected; unknown third-party domain increases supply-chain risk.

Evidence

  • install_url_hijack crx install_url_hijack=true; extension opens a URL on install — target unresolved.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension sets uninstall redirect URL — target unresolved.
  • privacy_policy_generic store Policy is Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email mujo.hydrov@gmail.com; no verified business domain; domain_age_ct not queried.
  • external_js_host crx js_external_hosts=[webbrowsertools.com]; unknown third-party domain in extension code.
  • broad_host_permission manifest host_permissions=[<all_urls>] combined with declarativeNetRequest; can strip CSP headers on all sites.
  • is_featured_by_google store Extension carries Google Featured badge, providing partial legitimacy signal.
  • operator_cluster_email_siblings api sibling_counts_by_dim.dev_email=2; same Gmail account linked to 2 extensions; compound sibling_count=0.

Permissions Breakdown

  • storage low Stores extension settings locally; minimal risk.
  • declarativeNetRequest medium Can modify/block network requests including CSP headers; significant capability.
  • <all_urls> (host_permission) high Broad host access enabling declarativeNetRequest rules to apply on every site visited.

Pillar Scores

Permissions6.50
Reputation6.50
Network2.00
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6 5.33 Medium review 2026-06-16
v3.4-rev 4.73 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA bdcc57a4225e…
Force block — not fired
Score recovered no
Elapsed 20.6s