Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Trusty Search Assistant for Amazon

hpmchbfaebbmmhepolfecmihamjfmofl
Risk Score
5.77
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 6,000
Rating 3.9
Last updated
Manifest version MV3
CSP present ❌ no
Developer casey1@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (Arbitrary Code Execution) in bundled underscore@1.8.3, no CSP, amplifier applies.
  • Privacy policy is Google's generic policy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy score.
  • last_updated missing: maintenance unknown, treated as worst-case >36 months → maximum maintenance score.
  • Amazon brand impersonation by unverified gmail developer with no business domain.
  • 5 external JS hosts referenced (gifer, lodash, openjsf, npms, underscorejs) with no CSP to constrain them.

Evidence

  • CVE critical+high in underscore@1.8.3; no CSP; underscore is DOM-manipulation-adjacent lib crx CVE-2021-23358 (critical ACE) and CVE-2026-27601 (high DoS) both unfixed. csp_present=false triggers ×1.5 amplifier.
  • Privacy policy is Google's own account policy, not scoped to this extension store scope_extension=false, data_collection=true, third_party_sharing=true → D-clause: +10.0 privacy pillar.
  • last_updated blank; months_since_update null store No update date available; scored as >36 months (maintenance=10.0) per conservative rubric.
  • Amazon brand impersonation by gmail developer store brand_mention.is_impersonation=true, developer_email=casey1@gmail.com, not verified, not featured owner.
  • 5 external JS hosts with no CSP (MV3) crx i.gifer.com, lodash.com, npms.io, openjsf.org, underscorejs.org — >3 distinct domains; no CSP constraint.
  • Free-webmail developer, no business domain store casey1@gmail.com; gmail dev + no business site → reputation floor ≥7.5 per rubric.
  • is_featured_by_google=true partially offsets reputation but impersonation and gmail still high-risk store Featured badge applied (-2.0 reputation) but floor rule for free-webmail keeps reputation at 8.0.
  • operator_cluster sibling_count by dev_email=1 indicates same email used across multiple extensions api sibling_counts_by_dim.dev_email=1; direct siblings=0 but email fingerprint shared.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Persists local extension state; no data exfil risk on its own.
  • content_scripts(*://*.amazon.*/s?*) medium Runs on Amazon search pages across 14 TLDs; scoped to amazon domains only.

Pillar Scores

Permissions1.30
Reputation8.00
Network2.50
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA c7376e507985…
Force block — not fired
Score recovered no
Elapsed 28.1s