Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Christmas Eve - Slot Machine

ibelidmkbnjmmpjgfibbdbkamgcbnjdm
Risk Score
4.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 26
Rating
Last updated 2025-10-22 (10 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@top.rodeo
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on cdn.cloudapi.stream admits data collection and third-party sharing but is not scoped to this extension — triggers D rule (+10.0 privacy).
  • No developer name listed; .rodeo TLD with CDN-hosted policy from a different domain raises accountability concerns.
  • 12 distinct external JS hosts referenced in bundle; includes topup.cloudapi.stream suggesting in-app purchase / monetization surface.
  • Sandbox CSP allows unsafe-inline and unsafe-eval, weakening sandboxed page isolation.
  • Very low install count (26) with no ratings and no developer identity — minimal accountability if extension behavior changes.

Evidence

  • privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
  • no_developer_name store developer_name is empty; reputation start 5.0 +1.0 for missing dev name.
  • developer_email_tld store support@top.rodeo uses .rodeo TLD; no verified business; +1.0 elevated-risk TLD.
  • sandbox_csp_unsafe manifest Sandbox directive includes unsafe-inline and unsafe-eval on script-src.
  • external_hosts_count crx 12 distinct registrable-domain external hosts including topup.cloudapi.stream and mines.cloudapi.stream.
  • host_permissions_dev_domains manifest 3 host_permissions point to developer-controlled cloudapi.stream subdomains and top.rodeo.
  • maintenance_3_6_months store months_since_update=10; falls in 6-12mo band → +3.5 maintenance.
  • code_findings_clean crx code_findings_raw empty, obfuscation_score=0.0 → code quality pillar 0.0.

Permissions Breakdown

  • identity low OAuth token access; low scope with no declared OAuth scopes in manifest.
  • host:https://www.googleapis.com/* low Google APIs access, consistent with identity permission.
  • host:https://wheel.cloudapi.stream/* medium Developer-controlled CDN subdomain; not a recognized third-party service.
  • host:https://mines.cloudapi.stream/* medium Developer-controlled CDN subdomain; game backend with unknown data handling.
  • host:https://top.rodeo/* medium Developer's own domain; unclear what data is sent there.

Pillar Scores

Permissions1.50
Reputation6.50
Network3.50
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:43
Listing SHA 94d110758e57…
Force block — not fired
Score recovered no
Elapsed