Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AI Toolbox: Folders, Prompts, Advanced Search & Export for AI Chats

jlalnhjkfiogoeonamcnngdndjbneina
Risk Score
2.93
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 30,000
Rating 4.7
Last updated 2026-08-27
Manifest version MV3
CSP present ❌ no
Developer support@infi-dev.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest permission enables observation of all ChatGPT network traffic including auth tokens.
  • uninstall_url_hijack detected — extension calls setUninstallURL to a third-party target.
  • JS external hosts include media.happyhourhub.co, twitter.com, x.com — unrelated to stated AI-chat function.
  • No CSP defined (MV3 default applies) but DOM-XSS innerHTML sink found in xsearch.js.
  • AI extension with scripting + webRequest on chatgpt.com processes sensitive conversation content.

Evidence

  • uninstall_url_hijack manifest uninstall_url_hijack=true; target null but setUninstallURL call to 3rd party detected — webstore +3.0.
  • external_hosts_scope_mismatch crx js_external_hosts includes media.happyhourhub.co, twitter.com, x.com — unrelated to AI-chat function.
  • dom_xss_sink crx innerHTML assigned from variable in xsearch.js; no CSP present, triggering +2.0 code-quality per FIX B.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied, floored at 2.0.
  • privacy_policy_adequate api Policy fetched, scoped, data_collection=true, retention=true, third_party_sharing=true; privacy pillar 0.0.
  • webRequest_on_chatgpt manifest webRequest + scripting scoped to chatgpt.com; can observe auth tokens and conversation payloads.
  • ai_extension_page_content store AI category extension with content_scripts on chatgpt.com processing sensitive user chat data.
  • host_geo_diversity api 3 countries (CA, DE, US); below threshold of 4 for geo-diversity penalty.

Permissions Breakdown

  • storage low Stores local extension data; expected for a productivity tool.
  • webRequest high Can observe network requests on declared hosts; broad capability even scoped.
  • activeTab medium Grants temporary access to the active tab; limited scope.
  • alarms low Schedules background tasks; low risk in isolation.
  • scripting medium Allows programmatic script injection into tabs; elevated but scoped to chatgpt.com.
  • host: https://chatgpt.com/* medium Scoped to ChatGPT; matches stated AI-chat-management function.
  • host: https://api.infi-dev.com/ai-toolbox/* low Developer's own API endpoint; expected for sync/auth.

Pillar Scores

Permissions4.50
Reputation2.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:47
Listing SHA 84af9f86e429…
Force block — not fired
Score recovered no
Elapsed