Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Braavos: Bitcoin & Starknet Wallet

jnlgamecbpmbajjfhmmmlhejkemejdma
Risk Score
4.68
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 100,000
Rating 4.9
Last updated 2026-02-04 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@braavos.app
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy could not be fetched — treated as no effective policy for scoring.
  • cookies permission + broad content_scripts (https://*/*) enables token/session harvesting on any site.
  • Dynamic script injection and new Function() constructor in background/content scripts raise XSS-pivot risk.
  • innerHTML DOM sink in 473.js is a DOM-XSS vector if upstream data is attacker-controlled.
  • 9 distinct external hosts across 4 countries contacted; some are third-party APIs (AWS, Starknet RPCs, fb.me).

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (fetch_error:HTTPError); scored as no effective policy (+10.0 privacy).
  • cookies_with_broad_content_scripts manifest cookies permission + content_scripts matching https://*/* creates high-risk session-data access surface.
  • uninstall_url_hijack crx uninstall_url_hijack==true; extension registers an uninstall URL redirect.
  • dynamic_script_injection crx script_src_dynamic in content.js and main.js; uses chrome.runtime.getURL — internal only, mitigates risk.
  • function_constructor crx new Function() in background.js and main.js; classic eval-equivalent pattern.
  • dom_xss_sink crx innerHTML assignment in 473.js; CSP present but no nonce hardening observed.
  • geo_diversity api JS external hosts span 4 countries (CA, IN, SG, US); wallet category, borderline acceptable but notable.
  • no_developer_name store developer_name is empty string; reputation start stays elevated without named entity.

Permissions Breakdown

  • storage low Standard wallet key/state persistence.
  • alarms low Background scheduling, low risk.
  • notifications low User-facing tx alerts, expected for wallet.
  • gcm low Push messaging; low standalone risk.
  • offscreen low Off-screen document support; low risk.
  • sidePanel low UI surface only.
  • tabs medium Can read active tab URL; moderate risk.
  • cookies high Cookie access; paired with broad content_scripts on https://*/*.

Pillar Scores

Permissions4.00
Reputation5.50
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA 31c67c690045…
Force block — not fired
Score recovered no
Elapsed 28.9s