Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

JSON Formatter

jjkimejmneecdeiijfnakkokbplconhf
Risk Score
2.32
Risk Level: Low
Recommendation: ✅ ALLOW
Category DeveloperTools
Installs 60
Rating
Last updated 2026-05-07 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@shiftshift.app
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Content script on <all_urls> injects into every site with no CSP, amplifying DOM-XSS risk.
  • Two innerHTML-from-variable sinks found; no CSP to mitigate XSS escalation.
  • Privacy policy discloses data collection and third-party sharing without retention period.
  • No developer display name listed; low install count limits trust signal.
  • MV3 + no CSP: network pillar +2.0 applied per v2 calibration rule (b).

Evidence

  • content_scripts_matches=<all_urls> manifest Extension injects into every URL; +2.0 HIGH permission for broad host access.
  • no_csp manifest content_security_policy is null; MV3+no CSP triggers +2.0 network penalty.
  • dom_sink_innerhtml_userctrl x2 crx innerHTML sinks in chunks/meta.js and content.js; no CSP present, raising code quality score.
  • privacy_policy_classification api Policy scoped to extension, data_collection=true, third_party_sharing=true, retention=false → +2.0.
  • verified_publisher+featured store Verified publisher and featured badge; reputation hard-floored at 2.0 per v2 rule 0a.
  • no_developer_name store developer_name is empty string; minor reputation concern offset by verified publisher.
  • threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves, not throwaway.
  • cve_findings_raw_empty crx No CVEs detected in bundled libraries; CVE pillar = 0.0.

Permissions Breakdown

  • storage low Stores user preferences locally; minimal risk.
  • content_scripts:<all_urls> high Injects scripts on all URLs; broad DOM access across every site visited.

Pillar Scores

Permissions3.30
Reputation2.00
Network2.00
Webstore0.00
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA 711ec3daa10a…
Force block — not fired
Score recovered no
Elapsed 21.2s