Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Chat with AI

ifhigdhiifbnjanhacoedbadhmlkjgae
Risk Score
5.17
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 10,000
Rating 4.8
Last updated 2025-11-28 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer multiaichat@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (not scoped to this extension), admits data collection and third-party sharing — effectively no real policy.
  • Uninstall and install URL hijacks flagged, consistent with traffic-monetization shell pattern.
  • Extension loads content from 7 external easytool.dev subdomains via JS — remote code surface with no CSP.
  • Free-webmail developer (gmail) with no verified publisher badge and no business website.
  • DOM-XSS sink (innerHTML with user-controlled variable) with no CSP to mitigate.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both install and uninstall URL hijacks present — classic monetization/traffic shell indicator.
  • js_external_hosts crx 7 external easytool.dev subdomains loaded; no CSP to constrain remote scripts.
  • privacy_policy_classification store Policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to extension.
  • developer_email store Free Gmail account (multiaichat@gmail.com); no verified publisher; no business domain.
  • dom_sink_innerhtml_userctrl crx innerHTML assigned from variable in iframe-service chunk; csp_present=false amplifies risk.
  • csp_present=false + MV3 manifest No content_security_policy declared; MV3 has strict default but no CSP in manifest.
  • is_featured_by_google store Featured badge present; partially offsets reputation concerns but does not verify publisher.
  • manifest_name/__MSG_appName__ manifest Manifest name and description use message keys — not directly readable; minor obfuscation signal.

Permissions Breakdown

  • storage low Local data persistence only; low direct harm.
  • sidePanel low Displays extension UI in Chrome side panel; limited capability.

Pillar Scores

Permissions0.60
Reputation6.50
Network3.50
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:48
Listing SHA 8ba05b3c1fbb…
Force block — not fired
Score recovered no
Elapsed