Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Smart Search Assistant: AI Partner Check

jlbpahgopcmomkgegpbmopfodolajhbl
Risk Score
3.13
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 20,000
Rating 4.6
Last updated 2026-05-20 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer charloesbharthwers@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (https://*/*) with content scripts on every page — high exfil surface.
  • AI extension calling api.smartsearcher.net processes page content; no CSP limiting outbound.
  • Developer email is free-webmail (gmail) with no developer name, reducing accountability.
  • Privacy policy admits third-party sharing but lacks data retention disclosure.
  • innerHTML DOM-XSS sink in content.js without CSP protection amplifies XSS risk.

Evidence

  • broad_host_access manifest host_permissions and content_scripts_matches both set to https://*/*; runs on every HTTPS site.
  • ai_extension_page_content manifest Category AI with content scripts on all pages posting to api.smartsearcher.net.
  • free_webmail_developer store Developer email charloesbharthwers@gmail.com; no developer name listed; gmail domain.
  • no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit extension-level CSP.
  • privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • dom_xss_sink crx js/content.js assigns innerHTML from variable without sanitization; no CSP mitigates.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partial trust discount applied.
  • manifest_name_localized manifest manifest_name=__MSG_name__ and manifest_description=__MSG_desc__; localized strings only.

Permissions Breakdown

  • storage low Stores local extension state; minimal risk on its own.
  • https://*/* high Broad host access across all HTTPS sites; content scripts inject into every page.
  • content_scripts_matches: https://*/* high Content scripts run on every HTTPS page, giving broad DOM read/write access.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:54
Listing SHA dd9f1374570d…
Force block — not fired
Score recovered no
Elapsed