Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Writing Assistant

icfibfjidabjcklhikmodelmopjmghgj
Risk Score
5.12
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 3,000
Rating 3.2
Last updated 2024-11-04 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@storkapp.me
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without scoping to this extension — scores maximum privacy risk.
  • Content script runs on <all_urls> giving access to every page; no CSP amplifies innerHTML XSS sinks.
  • Uninstall URL hijack detected — extension redirects user on uninstall to undisclosed third-party URL.
  • 19 months since last update; no active maintenance signal for an AI extension touching all pages.
  • AI writing assistant with broad page access, weak privacy posture, and low rating (3.2) raises data-exfil concern.

Evidence

  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls> — extension JS runs on every site visited.
  • privacy_policy_third_party_sharing crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (D).
  • uninstall_url_hijack crx uninstall_url_hijack=true; target unknown. Adds +3.0 webstore.
  • no_csp manifest content_security_policy is null; csp_present=false — amplifies innerHTML XSS findings.
  • dom_sink_innerhtml_userctrl_no_csp crx Two innerHTML sinks with csp_present=false trigger +2.0 code quality each (FIX B) — capped.
  • maintenance_stale store 19 months since update — falls in 12-24mo band (+6.0).
  • is_featured_by_google store Featured badge present; partially offsets reputation risk.
  • low_rating store Rating 3.2; rating_count not provided — no threshold discount applies.

Permissions Breakdown

  • storage low Stores local extension data; low intrinsic risk.
  • content_scripts:<all_urls> high Content script injected on all URLs — reads/modifies every page the user visits.

Pillar Scores

Permissions3.50
Reputation4.50
Network4.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA e1a55e2c03da…
Force block — not fired
Score recovered no
Elapsed 23.8s