Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Proxy Switcher

icpgekloenpkdgbbjnmjddbcmjglflkj
Risk Score
6.57
Risk Level: High
Recommendation: 🚫 BLOCK
Category PrivacyTool
Installs 10,000
Rating 4.2
Last updated 2026-03-20
Manifest version MV3
CSP present ❌ no
Developer anellenback1@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy+webRequest+<all_urls>: full browser traffic interception and rerouting capability.
  • Install & uninstall URL hijacks redirect to short.gy and go.ly monetization links.
  • Gmail developer with no business domain; privacy policy is generic Google policy, not extension-scoped.
  • 12 external JS hosts contacted including ip-api.com, ipinfo.io, go.ly — broad data exfil surface.
  • Privacy policy fetched but admits data collection and third-party sharing without scoping to this extension.

Evidence

  • proxy+webRequest+<all_urls> manifest Combination routes all browser traffic through attacker-controlled proxy and can observe every request.
  • install_url_hijack crx onInstalled opens https://proxyswitcher.short.gy/fUloTl — third-party monetization redirect.
  • uninstall_url_hijack crx setUninstallURL points to https://go.ly/ESgma — uninstall tracked by third-party link shortener.
  • gmail_developer_no_domain store Developer email anellenback1@gmail.com; no verified business domain; free-webmail threshold met.
  • generic_privacy_policy store Policy is Google's own account privacy page; scope_extension=false, admits data collection+3rd-party sharing.
  • 12_external_hosts crx js_external_hosts includes go.ly, ip-api.com, ipinfo.io, proxyswitcher.short.gy among 12 distinct domains.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
  • no_verified_publisher_badge store verified_publisher=true per store flag but developer is free-webmail gmail with no business domain.

Permissions Breakdown

  • storage low Stores proxy settings locally; standard low-risk.
  • proxy high Full control over all browser network routing; critical capability.
  • webRequest high Can observe all HTTP/S requests across every site visited.
  • webRequestAuthProvider high Can intercept and supply proxy authentication credentials.
  • <all_urls> high Broad host access amplifies proxy+webRequest to full traffic visibility.

Pillar Scores

Permissions8.50
Reputation7.50
Network6.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:18
Listing SHA bb7d069e9f1f…
Force block — not fired
Score recovered no
Elapsed 20.9s