Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Asaan Prompt

idpffgabghnkilmipgihgdhmdhcaleen
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 48
Rating 5.0
Last updated 2026-08-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer faani.work@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail developer (gmail) with no verified identity; privacy policy is a 609-char GitHub Gist with no extension-specific scope.
  • Nine host_permissions including *.workers.dev wildcard and Google Apps Script — arbitrary backend code can receive image/prompt data.
  • Runtime fetch from raw.githubusercontent.com / gist.githubusercontent.com enables remote config or code injection without CSP.
  • Privacy policy fetched but scope_extension=false and third_party_silence=true; data handling for AI inference calls undisclosed.
  • AI extension processes page images on Pinterest and forwards to multiple third-party AI endpoints (openrouter, pollinations, Anthropic).

Evidence

  • free_webmail_developer store Developer email faani.work@gmail.com; no verified publisher badge; no business domain.
  • privacy_policy_inadequate api Policy fetched (609 chars, GitHub Gist preview); scope_extension=false, data_collection=false, third_party_silence=true.
  • broad_host_permissions manifest 9 host_permissions including *.workers.dev wildcard and Google Apps Script endpoints.
  • remote_content_fetch manifest host_permissions include gist.githubusercontent.com and raw.githubusercontent.com; no CSP.
  • ai_data_exfil_surface manifest Content script on Pinterest pages; image data sent to openrouter.ai, pollinations, Anthropic, workers.dev.
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in popup.js; no CSP to mitigate.
  • no_csp manifest csp_present=false, MV3 default applies but remote host fetches weaken isolation.
  • low_install_count store Only 48 installs; unverified quality signal; tail-attack-surface anomaly not flagged but reach is minimal.

Permissions Breakdown

  • storage low Stores prompts/settings locally; expected for AI tool.
  • sidePanel low Opens side panel UI; matches stated feature.
  • clipboardWrite medium Auto-copies generated prompts; matches description but can silently overwrite clipboard.
  • contextMenus low Right-click menu trigger; low risk.
  • host: https://openrouter.ai/* medium AI routing API; sends image/text data to third-party aggregator.
  • host: https://text.pollinations.ai/* medium Free AI inference endpoint; data leaves device to unvetted service.
  • host: https://script.google.com/* + script.googleusercontent.com/* medium Google Apps Script — can run arbitrary server-side code; data exfil vector.
  • host: https://generativelanguage.googleapis.com/* low Official Google Gemini API; expected for AI prompt tool.
  • host: https://*.pinimg.com/* low Pinterest image CDN; matches Pinterest content-script scope.
  • host: https://*.workers.dev/* medium Cloudflare Workers wildcard — any worker subdomain; unknown backend code.
  • host: https://gist.githubusercontent.com/* + raw.githubusercontent.com/* medium Fetches raw GitHub content at runtime; risk of remote code/config loading.

Pillar Scores

Permissions3.30
Reputation6.50
Network4.50
Webstore2.50
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:18
Listing SHA 7413558cfc47…
Force block — not fired
Score recovered no
Elapsed