Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouTube to Perplexity AI

jgoiaakanloefcjgaecbmmifbnhecppl
Risk Score
4.65
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 292
Rating 3.5
Last updated 2025-07-21 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer youranotherdataguy@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google's generic privacy policy used — does not scope data collection to this extension at all.
  • Brand impersonation: unverified Gmail dev references YouTube and Perplexity AI brands.
  • Free-webmail developer (Gmail) with no verified business identity or domain.
  • install_url_hijack flag set: onInstalled may open a third-party URL.
  • No CSP on MV3 extension — slight content-injection risk via scripting permission on YouTube.

Evidence

  • privacy_policy_generic store Policy URL is Google's own account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — scores +10.0 under v3.5 rule D.
  • brand_impersonation store brand_mention.is_impersonation=true; brands youtube+perplexity; developer not verified_publisher nor featured. +2.0 Reputation.
  • free_webmail_developer store Developer email youranotherdataguy@gmail.com; no business website; free-webmail floor applies (Reputation >= 7.5).
  • install_url_hijack crx install_url_hijack=true; target null. Likely opens onboarding/promo page on install. +2.0 Webstore.
  • no_csp manifest content_security_policy=null on MV3; no additional network risk added per v2 (MV3 strict default), but scripting perm on YouTube less constrained.
  • low_installs_ai_extension store 292 installs; AI category processing page content from YouTube; +2.5 Webstore for AI/Gen-AI content processing.
  • maintenance_3_6mo store months_since_update=11; falls in 6-12mo band; +3.5 Maintenance.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; no CVEs detected. Code quality pillar=0.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction only.
  • tabs medium Can read tab URLs and titles across the browser.
  • scripting medium Can inject scripts into pages; risk mitigated by narrow host_permissions.
  • https://www.youtube.com/* medium Broad access to all YouTube pages; needed for transcript extraction.
  • https://youtube.com/* medium Duplicate YouTube host permission.
  • https://www.perplexity.ai/* low Destination AI site; matches stated function.

Pillar Scores

Permissions2.30
Reputation8.00
Network2.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA fc2293222a1a…
Force block — not fired
Score recovered no
Elapsed 23.6s