Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MangaTrans

hoagaedakmopbokhnbjhoakgpdijahpg
Risk Score
5.26
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 11
Rating 5.0
Last updated 2026-06-03 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer deepak.chowdary147@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returns error (fetched==false); effective policy unknown — scored +10.0.
  • Free-webmail dev (gmail) with no verified business; brand_mention flags GPT-4/Claude impersonation.
  • <all_urls> host permission with content_scripts on every page enables broad data access.
  • AI extension contacts api.anthropic.com and api.openai.com; page content may be transmitted to external AI APIs.
  • Only 11 installs with HIGH-tier permission (small_install_high_perm) raises tail-attack-surface concern.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returns HTTPError; policy cannot be evaluated — worst-case score applied.
  • free_webmail_dev store Developer email deepak.chowdary147@gmail.com; no verified business domain; not verified publisher.
  • brand_impersonation store brand_mention.is_impersonation=true; brands gpt-4 and claude mentioned; confirmed_owner=false.
  • host_permission_all_urls manifest <all_urls> host permission + content_scripts on *://*/* grants read/write on every page.
  • ai_page_content_exfil manifest AI translation extension contacts api.anthropic.com and api.openai.com; page image/text sent externally.
  • small_install_high_perm store Only 11 installs with HIGH-tier permission; anomaly flag raised by install_perm_anomaly.
  • no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit hardening declared.
  • cve_none crx cve_findings_raw is empty; no bundled vulnerable libraries detected.

Permissions Breakdown

  • activeTab low Access only to the currently active tab on user action; scoped and low risk.
  • storage low Local storage for settings/state; no exfil risk alone.
  • <all_urls> (host_permission) high Grants content script injection on every site; broad capability paired with AI processing.

Pillar Scores

Permissions5.50
Reputation7.50
Network3.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:26
Listing SHA e644bad1139a…
Force block — not fired
Score recovered no
Elapsed