Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Claude Limit & Usage Tracker - ClaudeKarma

hoffoefgnaakaafdfjpnjdkclhjkebjn
Risk Score
3.23
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 10,000
Rating 4.9
Last updated 2026-05-19 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer tabkarma@duck.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: 'claude' brand mentioned in name/description; dev is not Anthropic and not verified owner.
  • Uninstall URL hijack flag set (target unknown); install URL hijack also flagged — destination unverified.
  • Developer identity weak: no dev name, duck.com privacy-relay email, no verified business domain.
  • Privacy policy scoped to extension but discloses third-party sharing without specifying recipients or data retained.
  • 8 external JS hosts referenced (tokenkarma.app, twitter, github, linkedin, mozilla, youtube) — surface wider than stated function.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'claude'; confirmed_owner=false; developer is not Anthropic.
  • install_uninstall_url_hijack crx install_url_hijack=true AND uninstall_url_hijack=true; targets are null — destination unverifiable.
  • developer_identity store developer_name empty; email tabkarma@duck.com is a privacy-relay address; no verified business.
  • verified_publisher store verified_publisher=true; provides -1.0 reputation discount (not full -3.0 due to impersonation context).
  • privacy_policy_third_party api Policy fetched, scoped, no data_collection, but third_party_sharing=true and retention=false.
  • external_hosts crx 8 external JS hosts: claude.ai, tokenkarma.app, static.tokenkarma.app, github, twitter, linkedin, mozilla, youtube.
  • host_permission_scope manifest host_permissions limited to https://claude.ai/*; content_scripts match same origin — appropriately narrow.
  • cve_and_code_clean crx cve_findings_raw empty; code_findings_raw empty; obfuscation_score=0.0; MV3 with strict CSP.

Permissions Breakdown

  • storage low Stores local usage tracking data; no remote exfil observed.
  • alarms low Used for periodic limit-check scheduling; low impact.
  • notifications low Alerts user on limit events; no cross-site risk.
  • https://claude.ai/* medium Host permission scoped to claude.ai only; matches stated function but enables content reads.

Pillar Scores

Permissions1.60
Reputation6.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA ea0a961bf2b5…
Force block — not fired
Score recovered no
Elapsed 20.8s