Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouTube Shopping

ighjodkhjaliganonnlmdedfgnomaebi
Risk Score
2.82
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 50,000
Rating 4.3
Last updated 2026-04-10 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer yt-shopping-creator-extension-support@google.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (policies.google.com) — not scoped to this extension; scope_extension==false with data_collection+third_party_sharing==true triggers +10.0 privacy.
  • brand_mention flags 'youtube' as impersonation (confirmed_owner==false); developer email is @google.com but verified_publisher==false, creating unresolved ownership ambiguity.
  • No CSP present (MV3 default mitigates somewhat, but no explicit policy declared).
  • Install count 50K provides moderate blast radius if extension is ever compromised or transferred.
  • Generic Google privacy policy admits data collection and third-party sharing without extension-specific scope.

Evidence

  • brand_impersonation_flag store brand_mention.is_impersonation=true for 'youtube'; confirmed_owner=false despite @google.com email and non-verified publisher status.
  • generic_privacy_policy store policies.google.com/privacy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
  • no_csp manifest content_security_policy is null; MV3 provides strict default but no explicit CSP declared. Network +2.0 (MV2+no-CSP rule does NOT apply to MV3).
  • minimal_permissions manifest Only 'activeTab' declared; no host_permissions, no content_scripts. Very low capability surface.
  • clean_code_scan crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[]. No malicious indicators detected.
  • no_cve_findings crx cve_findings_raw=[]; no vulnerable libraries bundled.
  • recently_updated store months_since_update=2; maintenance pillar score=0.0.
  • unverified_publisher store verified_publisher=false, is_featured_by_google=false; no reputation discounts applicable.

Permissions Breakdown

  • activeTab low Only accesses the current tab on explicit user action; minimal persistent access.

Pillar Scores

Permissions0.30
Reputation5.00
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6 2.82 Low review 2026-06-16
v3.4-rev 2.76 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA aa584a1c76b9…
Force block — not fired
Score recovered no
Elapsed 19.2s