Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hide Discord Sidebar

kaaohmdnmbdagpnenakakpkinddjmenp
Risk Score
4.23
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 20,000
Rating 4.4
Last updated
Manifest version MV3
CSP present ✅ yes
Developer patrickxchong@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; data collection and 3rd-party sharing admitted.
  • Brand impersonation flag: extension explicitly names Discord without verified ownership; dev uses free Gmail.
  • last_updated missing — maintenance risk cannot be confirmed; could be stale.
  • Free-webmail developer (Gmail) with no verified business presence raises accountability gap.
  • Google Featured badge is positive but does not offset privacy policy deficiency.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, brands_mentioned=[discord], dev domain=gmail.com
  • privacy_policy_generic store Policy is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 D)
  • free_webmail_developer store developer_email=patrickxchong@gmail.com; no verified business domain; Reputation +1.5
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount
  • last_updated_missing api months_since_update=null; maintenance pillar scored at 6.0 (6-12mo band as conservative default)
  • no_threat_intel_hits crx bad_host_hits=[], monetization_hits=[], affiliate_hits=[], sibling_count=0
  • csp_strict manifest script-src 'self'; object-src 'self' — no remote script sources, MV3 with CSP present
  • code_clean crx code_findings_raw=[], obfuscation_score=0.0, cve_findings_raw=[], js_libraries_detected=[]

Permissions Breakdown

  • scripting medium Allows JS injection into pages; scoped to discord.com only, limiting blast radius.
  • storage low Local extension state storage; no cross-site risk.
  • *://*.discord.com/* (host) medium Single-domain host access matching stated function; no broader web exposure.

Pillar Scores

Permissions2.00
Reputation6.50
Network0.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn1361b2ccdp727562726963xsx 4.28 Medium review 2026-08-28
v3.6 4.23 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA 4ec951b76fee…
Force block — not fired
Score recovered no
Elapsed 20.5s