Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Auto Quality for YouTube™

iaddfgegjgjelgkanamleadckkpnjpjc
Risk Score
6.95
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 100,000
Rating 3.3
Last updated 2025-02-25 (18 months ago)
Manifest version MV3
CSP present ✅ yes
Developer oneted.dev@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — scores max privacy risk (+10.0)
  • Uninstall and install URL hijack both active — classic monetization/redirect shell pattern
  • YouTube brand impersonation by unverified Gmail developer with no confirmed ownership
  • webRequest + scripting + <all_urls> grants full page read/modify capability on every site
  • 18-month stale extension with broad permissions and a non-scoped admit-all privacy policy

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hijacks flagged; classic monetization/redirect shell indicator (+3.0 Webstore)
  • privacy_policy_classification api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (D rule)
  • brand_mention impersonation store YouTube trademark in title, developer_domain=gmail.com, confirmed_owner=false, is_impersonation=true → +2.0 Reputation
  • developer email free-webmail store oneted.dev@gmail.com with no verified business; free-webmail dev raises Reputation floor to 7.5
  • webRequest + <all_urls> + scripting manifest HIGH permissions paired with broad host access; ×1.2 amplifier applied; no justified-broad discount for Entertainment
  • months_since_update=18 store Exactly 18 months → Maintenance +6.0 (12-24mo band); also triggers v3.5E cap on any verified-publisher discount
  • js_external_hosts crx Contacts api.megaxt.com, www.megaxt.com, yt.megaxt.com — 3 distinct domains all under megaxt.com
  • install_perm_anomaly api 100k installs + HIGH-tier permissions confirmed; not small-install anomaly but broad capability at scale

Permissions Breakdown

  • webRequest high Intercepts all network requests; paired with <all_urls> amplifies risk ×1.2
  • <all_urls> (host_permission) high Broad host access covering every site the user visits
  • tabs medium Access to tab URLs and metadata across all tabs
  • activeTab medium Grants script access to currently active tab on interaction
  • scripting medium Can inject JS/CSS into pages; combined with <all_urls> is high capability
  • declarativeNetRequest medium Can block/redirect network requests declaratively
  • storage low Local extension storage; low standalone risk
  • alarms low Scheduled tasks; low risk on its own

Pillar Scores

Permissions8.40
Reputation7.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:08
Listing SHA c8320c48fb96…
Force block — not fired
Score recovered no
Elapsed