Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DeepSeek AI Chat

jmpcodajbcpgkebjipbmjdoboehfiddd
Risk Score
4.32
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category AI
Installs 1,000
Rating 4.0
Last updated 2025-02-04 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@ai-chat-bot.pro
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: claims DeepSeek affiliation but developer domain is ai-chat-bot.pro with no confirmed ownership.
  • Privacy policy is Google's generic policy — scope_extension=false, data_collection=true, third_party_sharing=true; triggers +10.0 privacy per v3.5 rule D.
  • Install URL hijack opens ai-chat-bot.pro/welcome on install; uninstall URL hijack also set — monetization shell indicators.
  • No developer name listed; generic AI-chat domain with no verified publisher or featured badge.
  • 18 months since last update with no CSP and external JS host (ai-chat-bot.pro) creating persistent update surface.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'deepseek'; developer domain ai-chat-bot.pro is not confirmed owner.
  • install_url_hijack crx onInstalled opens https://ai-chat-bot.pro/welcome; uninstall_url_hijack=true. Monetization shell pattern.
  • generic_privacy_policy store Policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true. Triggers +10.0.
  • no_developer_name store developer_name is empty string; no verified publisher; no featured badge.
  • stale_extension store months_since_update=18; maintenance pillar +6.0 (12-24 month band).
  • external_js_host crx js_external_hosts=['ai-chat-bot.pro']; no CSP; MV3 so no +2.0 MV2 penalty but external host present.
  • no_csp crx content_security_policy=null; csp_present=false on MV3 extension with external JS host.
  • ai_extension_page_content store AI/Gen-AI category extension; Webstore +2.5 for AI extension processing page content.

Permissions Breakdown

  • storage low Local key-value storage only; no cross-origin data access.

Pillar Scores

Permissions1.00
Reputation9.00
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:50
Listing SHA fe5b8a1daced…
Force block — not fired
Score recovered no
Elapsed