Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Disable Content-Security-Policy

ieelmcmcagommplceebfedjlakkhpden
Risk Score
4.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 70,000
Rating 3.5
Last updated 2024-09-03 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer phil@philgrayson.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Core function strips CSP from all sites visited, eliminating XSS defenses for users who forget to disable it.
  • Privacy policy is Google's generic account policy — completely unscoped to this extension (scope_extension=false, data_collection=true, third_party_sharing=true).
  • browsingData permission allows wiping cookies/cache/history with no apparent functional need beyond CSP disabling.
  • 21 months since last update; extension is approaching stale territory with no changelog evidence.
  • External host contact to web.whatsapp.com is unexplained for a CSP-disabling developer tool.

Evidence

  • core_function_security_risk manifest Extension's stated purpose is to disable CSP via declarativeNetRequest header removal — exposes users to XSS on every visited site.
  • privacy_policy_generic store Policy URL is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true per classification.
  • browsingData_unexplained manifest browsingData permission declared; no functional justification for a CSP-stripping dev tool.
  • external_host_unexplained crx js_external_hosts includes web.whatsapp.com — no clear reason for a CSP-disable tool to reference WhatsApp.
  • maintenance_stale store Last updated September 2024; 21 months since update (6-12mo band exceeded, 12-24mo = +6.0).
  • no_csp_mv3 crx content_security_policy is null; MV3 provides strict default so no v2 network penalty applies.
  • rating_below_threshold store Rating 3.5; no confirmed count so +1.0 rating<3.0 rule not triggered, but low satisfaction signal.
  • cve_findings_empty crx No CVEs found in bundled libraries; cve_findings_raw is empty.

Permissions Breakdown

  • storage low Stores extension settings locally; minimal risk.
  • activeTab medium Access to currently active tab on user interaction; scoped but grants page content access.
  • browsingData high Can clear cookies, cache, history — significant user data destruction capability.
  • declarativeNetRequest medium Can modify/block network requests including CSP headers; core stated function but powerful.

Pillar Scores

Permissions5.50
Reputation5.00
Network0.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6 4.53 Medium review 2026-06-16
v3.4-rev 4.41 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA d5b358ccde0f…
Force block — not fired
Score recovered no
Elapsed 21.2s