Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AIPRM for Claude

iknoeobkamkodhjpieieelgaechlkeaj
Risk Score
5.35
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 30,000
Rating 3.4
Last updated 2026-05-18 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer hello@aiprm.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + third-party sharing without extension-specific scoping (v3.5 rule D → +10.0 privacy).
  • Brand impersonation: extension uses 'Claude' (Anthropic brand) without confirmed ownership and is not verified publisher.
  • Install-URL hijack: onInstalled redirects to https://claude.ai, a third-party URL (+2.0 webstore).
  • Uninstall-URL hijack flagged (+3.0 webstore); combined with install hijack forms monetization-shell signal.
  • 12 distinct external JS hosts including dev/test/staging AIPRM subdomains; no CSP on MV3 extension (+2.0 network; dom_sink XSS risk elevated).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'claude'; confirmed_owner=false; not verified publisher.
  • privacy_policy_scope_mismatch api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D +10.0.
  • install_url_hijack crx install_url_hijack=true, target=https://claude.ai; onInstalled opens third-party URL.
  • uninstall_url_hijack crx uninstall_url_hijack=true (target null); +3.0 webstore per rubric.
  • dom_xss_sinks_no_csp crx 2x dom_sink_innerhtml_userctrl in readability.js and inject.js; csp_present=false amplifies risk.
  • external_host_count crx 12 distinct external JS hosts (api/app/dev-api/dev-app/test-api/test-app/forum.aiprm.com + github, google, apache, claude.ai).
  • no_developer_name store developer_name is empty string; only email hello@aiprm.com provided.
  • rating_below_threshold store Rating 3.4 (below 4.0); rating_count unknown but 30K installs with low rating is a negative signal.

Permissions Breakdown

  • activeTab low Limited to currently active tab on user action; low standalone risk.
  • contextMenus low Adds right-click menu entries; no data access risk alone.
  • declarativeNetRequestWithHostAccess high Can intercept/redirect network requests on permitted hosts (claude.ai); significant capability.
  • https://claude.ai/* medium Host permission scoped only to claude.ai; narrows blast radius but enables full page content access on that domain.

Pillar Scores

Permissions5.00
Reputation6.50
Network5.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA f4c1e2ce0da9…
Force block — not fired
Score recovered no
Elapsed 26.0s