Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PSP Detector

iblfofcbjioicompkmafdehbdakdbjle
Risk Score
1.98
Risk Level: Low
Recommendation: ✅ ALLOW
Category DeveloperTools
Installs 580
Rating 5.0
Last updated 2026-05-31 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer google@adamstiskala.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • install_url_hijack flag set (target null); possible onInstalled redirect not confirmed.
  • Privacy policy hosted on free GitHub Pages, lacks retention disclosure and third-party sharing detail.
  • Developer email uses custom domain prefix 'google@' which could cause brand confusion.
  • Small install base (580) limits blast radius but reduces reputational validation.
  • Domain age CT lookup failed; developer domain age unverifiable.

Evidence

  • install_url_hijack crx install_url_hijack=true but install_url_target=null; no confirmed 3rd-party redirect URL observed.
  • privacy_policy_classification api Policy fetched, scoped to extension, data_collection=true, retention=false, third_party_silence=true.
  • no_bad_hosts api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean.
  • code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty, cve_findings_raw empty.
  • csp_present manifest script-src 'self'; object-src 'self'; — strict MV3 CSP, no unsafe-eval or remote CDN.
  • permissions_minimal manifest Only activeTab, favicon, scripting, storage. No host_permissions or broad URL patterns.
  • developer_domain api adamstiskala.com resolves, looks_throwaway=false; CT lookup failed (HTTPError), age unverified.
  • operator_cluster api sibling_count=0; no related extensions under same fingerprint.

Permissions Breakdown

  • activeTab low Only accesses current tab on user action; no persistent host access.
  • favicon low Read-only favicon access; minimal data exposure.
  • scripting medium Can inject scripts into pages, but scoped to activeTab without broad host permissions.
  • storage low Local extension storage only; no cross-origin data risk.

Pillar Scores

Permissions1.60
Reputation5.00
Network0.00
Webstore2.00
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA 175690498b89…
Force block — not fired
Score recovered no
Elapsed 19.1s