Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Topease - AI Assistant for Foreign Trade Client Development

injehaoimkkdminimmmcmbfhcmppjpdf
Risk Score
6.64
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs 1,000
Rating 5.0
Last updated 2026-07-30 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer shuxinhao2000@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (Arbitrary Code Execution) with no CSP and DOM-XSS sink present — high exploitability.
  • Three medium jQuery CVEs (XSS) in bundled jquery@1.9.1; extension runs on <all_urls> amplifying blast radius.
  • Privacy policy is Google's own policy (not scoped to this extension) and admits data collection + 3rd-party sharing — score +10.
  • Free-webmail developer (gmail) with no verified publisher badge; developer domain unresolvable — low accountability.
  • scripting + <all_urls> + content_scripts on <all_urls> gives full arbitrary JS injection across every visited site.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical: Arbitrary Code Execution); fixed in 1.12.1.
  • high_cve_underscore crx underscore@1.8.3 has CVE-2026-27601 (high: DoS via recursion); fixed in 1.13.8.
  • medium_cves_jquery crx jquery@1.9.1 has 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed in 3.5.0.
  • dom_xss_sink_no_csp crx innerHTML from variable in libs/popup.js; no CSP present — DOM-XSS sink unmitigated, scores +2.0 elevated.
  • generic_google_privacy_policy store Privacy URL is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.
  • broad_host_scripting manifest scripting + <all_urls> host_permissions + content_scripts on <all_urls> — full page JS injection on every site.
  • free_webmail_dev_no_verified store Developer email shuxinhao2000@gmail.com; no verified publisher badge; developer_domain_info null.
  • ai_extension_page_content store AI assistant extension with <all_urls>; processes page content with no scoped privacy disclosure.

CVE Exposures (5)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • scripting high Can inject arbitrary JS into any page; paired with <all_urls> this is maximum code-execution reach.
  • tabs medium Access to URL, title, and navigation of all open tabs.
  • storage low Persistent local storage; low risk in isolation.
  • <all_urls> (host_permissions) high Broad host access amplifies scripting and content_scripts to every site the user visits.

Pillar Scores

Permissions6.50
Reputation6.50
Network5.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure8.25

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 16:07
Listing SHA 959379585d41…
Force block — not fired
Score recovered no
Elapsed