Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Netskope DEM Browser Extension

jeicldcjlbmhknbpgkokgcbnipioijee
Risk Score
5.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 1,000
Rating 5.0
Last updated 2026-03-06 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer yichunw@netskope.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed; classified as unfetched → maximum privacy score (10.0).
  • webRequest + scripting + <all_urls> on MV3 allows full traffic observation and script injection into every site.
  • Uninstall URL hijack detected (uninstall_url_hijack=true) — redirects user on removal.
  • External JS hosts include hashed domain and devint-automation subdomain; no CSP present on MV3.
  • Not a verified publisher; individual developer email on corporate domain, low install count.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returned HTTP error; classified as fetched=false → pillar score 10.0.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null — extension registers an uninstall redirect.
  • high_permissions_combo manifest webRequest + scripting + <all_urls>: observe and modify all network traffic and inject scripts everywhere.
  • external_js_hosts crx 7 external JS hosts including hashed domain aaa0272bbb..., devint-automation.boomskope.com, and public sites.
  • no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.
  • not_verified_publisher store verified_publisher=false, is_featured_by_google=false; individual email on netskope.com domain.
  • low_install_count store Only 1,000 installs for an enterprise security tool with high-tier permissions.
  • no_bad_hosts_no_cves api threat_intel shows no bad_host_hits, no monetization, no affiliate hits; cve_findings_raw empty.

Permissions Breakdown

  • storage low Local data persistence only.
  • alarms low Scheduling/polling; minimal risk.
  • scripting medium Can inject scripts into pages; paired with <all_urls> elevates capability.
  • declarativeNetRequest medium Network rule evaluation; less risky than webRequestBlocking.
  • webRequest high Observe all network traffic across all URLs; broad surveillance capability.
  • webNavigation medium Track user navigation events across all tabs.
  • tabs medium Access tab URLs, titles, and state across all tabs.
  • offscreen low Background DOM operations; low direct risk.
  • system.memory low Read system memory info; DEM telemetry use case.
  • system.cpu low Read CPU metrics; DEM telemetry use case.
  • <all_urls> high Host permission covering all sites; combined with webRequest and scripting is maximum reach.

Pillar Scores

Permissions7.50
Reputation4.50
Network4.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-06 18:33
Listing SHA aa983f66f14a…
Force block — not fired
Score recovered no
Elapsed