Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cubo Conecta

imhedlpapnopjkbnhojdcknleolmjnbg
Risk Score
4.04
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 334
Rating 5.0
Last updated 2026-08-27
Manifest version MV3
CSP present ❌ no
Developer contato@cubocrm.com.br
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and third-party sharing (Privacy +10.0).
  • Brand impersonation: WhatsApp mentioned in description/content-scripts but developer is unverified as Meta (Reputation +2.0).
  • Uninstall URL hijack flag set (uninstall_url_hijack=true) — redirects user on removal (Webstore +3.0).
  • Content script on web.whatsapp.com can read/modify all WhatsApp Web content including messages and contact data.
  • No content_security_policy (MV3 default applies but CSP absent increases risk surface for injected scripts).

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL() set to third-party target; triggers +3.0 Webstore penalty.
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true for WhatsApp; developer not confirmed as Meta owner.
  • generic_google_privacy_policy api Policy URL is myaccount.google.com/privacypolicy — fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 D rule).
  • content_script_whatsapp manifest Content script injected into web.whatsapp.com — can read messages, contacts, session tokens.
  • no_cve_findings crx cve_findings_raw empty; vue 3.5.25 bundled — no known CVEs detected.
  • obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty; code quality appears clean.
  • developer_domain_resolves api cubocrm.com.br resolves, looks_throwaway=false; legitimate Brazilian CRM business signal.
  • no_operator_siblings api operator_cluster.sibling_count=0; no cluster risk.

Permissions Breakdown

  • storage low Local key-value storage only; no cross-site data exposure.
  • host: https://next.cubosuite.com.br/* low Scoped to developer's own backend domain; consistent with CRM function.
  • content_script: https://web.whatsapp.com/* medium Reads/modifies WhatsApp Web DOM; can intercept messages and contacts.
  • content_script: https://www.google.com/maps/* low Scoped to Maps; limited data exposure risk.
  • content_script: https://www.google.com/search* low Scoped to Google Search results; moderate data exposure.
  • content_script: https://www.google.com/sorry/* low CAPTCHA page only; negligible risk.

Pillar Scores

Permissions2.00
Reputation6.50
Network1.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:49
Listing SHA 77d425881bcf…
Force block — not fired
Score recovered no
Elapsed