Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Multi-View Dashboard

jmkhjcdcmejccfblfkhljjplbndnhhhh
Risk Score
4.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 42
Rating 5.0
Last updated 2026-07-30 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer ozguraka92@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + <all_urls>: can read/write session cookies for every website visited — session hijack risk.
  • install_url_hijack: extension opens unknown URL on install, possible traffic/affiliate redirect.
  • Free-webmail Gmail dev (ozguraka92@gmail.com), no verified publisher, no recognized org.
  • Only 42 installs with high-tier permissions — classic tail-attack-surface anomaly.
  • Privacy policy discloses third-party sharing but omits data retention period.

Evidence

  • cookies + <all_urls> manifest cookies permission combined with <all_urls> host access enables reading/writing session cookies across all sites.
  • install_url_hijack crx install_url_hijack == true; extension opens a URL on install. Target URL not captured — destination unknown.
  • free-webmail developer store Developer email ozguraka92@gmail.com; no verified publisher badge; no recognized organization.
  • small_install_high_perm anomaly api 42 installs with high-tier permissions (cookies, declarativeNetRequest, <all_urls>); unusual ratio.
  • third_party_sharing disclosed without retention store Privacy policy: third_party_sharing=true, retention=false. Sharing acknowledged but retention unspecified.
  • no CSP manifest content_security_policy is null; MV3 default CSP applies but no explicit hardening declared.
  • content_scripts scoped to Twitter/X/Instagram only manifest Content scripts limited to social platforms; narrower than full <all_urls> host permission.
  • no CVEs, no bad hosts, no obfuscation crx cve_findings_raw empty, threat_intel clean, obfuscation_score 0.0, code_findings_raw empty.

Permissions Breakdown

  • storage low Standard local data persistence; low risk alone.
  • unlimitedStorage low Expands storage quota; minimal standalone risk.
  • cookies high Can read/write cookies across all sites with <all_urls>; significant session-hijack risk.
  • declarativeNetRequest medium Can modify/block network requests; lower risk than webRequest but still significant.
  • declarativeNetRequestFeedback medium Reveals which rules matched which requests; minor info disclosure.
  • notifications low Can display OS notifications; low direct harm.
  • alarms low Schedules background tasks; low risk alone.
  • <all_urls> high Host permission covering every site; amplifies cookies and declarativeNetRequest to full scope.

Pillar Scores

Permissions7.00
Reputation7.50
Network2.00
Webstore4.00
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 11:45
Listing SHA 591c7e4b485d…
Force block — not fired
Score recovered no
Elapsed