Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Open Slack in Browser, not App

jkgehijlkoolgcjifalbiicaomkngakb
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 4,000
Rating 5.0
Last updated 2024-10-16 (20 months ago)
Manifest version MV3
CSP present ❌ no
Developer user.2g3t@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
  • Brand impersonation: 'slack' mentioned, developer not a confirmed Slack owner, free-webmail gmail dev.
  • Shell pattern flagged by description_promise.is_shell_pattern; sparse manifest raises authenticity concern.
  • Stale: 20 months since last update on MV3 extension with 4K installs.
  • Developer identity unverifiable: free-webmail alias email, no business domain, no verified-publisher badge.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['slack']; confirmed_owner=false; dev domain is gmail.com.
  • privacy_policy_generic store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • shell_pattern store description_promise.is_shell_pattern=true; manifest_description equals extension title; no mismatches but suspicious minimal footprint.
  • free_webmail_dev store developer_email=user.2g3t@gmail.com; no business website; dev name='yume'; no verified publisher badge.
  • stale_extension store months_since_update=20; maps to +6.0 maintenance (6-24 mo band).
  • content_scripts_scoped manifest content_scripts limited to *.slack.com only; no broad host permissions; permissions[] empty.
  • no_cve_no_obfuscation crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0; single JS file, no external hosts beyond github.com.
  • no_bad_hosts_no_monetization api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; operator sibling_count=0.

Permissions Breakdown

  • content_scripts: *.slack.com/archives/*, *.slack.com/ssb/redirect* medium Scoped to slack.com subdomains only; low breadth but can read/modify Slack pages.

Pillar Scores

Permissions1.00
Reputation7.50
Network0.00
Webstore6.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA 37a61911b9aa…
Force block — not fired
Score recovered no
Elapsed 21.5s