Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Write Brain: AI Writing Assistant

hoifabdggfdbeejjnachknneilikeobk
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 211
Rating 5.0
Last updated 2023-10-25 (32 months ago)
Manifest version MV3
CSP present ❌ no
Developer andrew@internuity.net
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Content script runs on <all_urls> — reads and can modify all page content including passwords and PII.
  • AI extension: user text from any page may be sent to writebrain.io for processing.
  • Extension last updated 32 months ago — stale, no recent security fixes.
  • Privacy policy does not disclose retention period; third-party sharing silence noted.
  • No developer display name — reduces accountability.

Evidence

  • content_scripts_all_urls manifest content_scripts matches <all_urls> — broad read/write access to every page visited.
  • ai_page_content_processing manifest AI writing assistant with <all_urls> injection sends page text to writebrain.io.
  • stale_extension store Last updated October 2023, 32 months ago — no maintenance signal.
  • no_csp manifest content_security_policy is null — no CSP hardening on MV3 extension.
  • privacy_retention_missing api Privacy policy fetched and scoped but retention field is false; third_party_silence=true.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • no_bad_hosts_or_cves crx No bad host hits, no CVE findings, no code findings, obfuscation_score=0.
  • featured_by_google store is_featured_by_google=true; partial reputation signal.

Permissions Breakdown

  • storage low Stores local extension state; low standalone risk.
  • activeTab low Access limited to currently active tab on user action.
  • host: https://writebrain.io/* low Scoped to own service domain only.
  • host: https://dev.writebrain.io/* low Scoped to dev subdomain of own service.
  • content_scripts: <all_urls> high Content script injected on every page — can read/modify all page content including sensitive data.

Pillar Scores

Permissions3.30
Reputation5.50
Network2.50
Webstore2.50
Maintenance8.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA fb51218da943…
Force block — not fired
Score recovered no
Elapsed 18.5s