Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AI Exporter: Save ChatGPT, Gemini to PDF, Word, MD and Notion

kagjkiiecagemklhmhkabbalfpbianbe
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 100,000
Rating 4.8
Last updated 2026-06-15
Manifest version MV3
CSP present ✅ yes
Developer mrsoniceman@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true — admits broad data sharing without scoping to this extension (Privacy +10.0)
  • brand_mention.is_impersonation=true (ChatGPT/Gemini) with gmail dev email and no verified business identity (Reputation +2.0)
  • Broad host_permissions *://*/* on an AI content-scraping extension with cookies permission — can read/exfil any site session
  • CSP sandbox allows unsafe-eval and unsafe-inline on script-src; DOM-XSS sink (innerHTML) found in bundled JS
  • Uninstall URL hijack detected (uninstall_url_hijack=true) and developer is free-webmail gmail with no developer name

Evidence

  • privacy_policy_admits_third_party_sharing_without_scope api Policy fetched from saveai.net/privacy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0 (D rule)
  • brand_impersonation_gmail_dev store brand_mention.is_impersonation=true (chatgpt,gemini); developer is mrsoniceman@gmail.com with no developer name; verified_publisher=true
  • cookies_plus_all_urls manifest cookies permission + *://*/* host_permissions; ×1.2 amplifier applied — can read any site session cookie
  • csp_unsafe_eval_unsafe_inline crx sandbox CSP contains unsafe-eval and unsafe-inline on script-src; dom_sink_innerhtml_userctrl in code_findings_raw → Code +2.0
  • uninstall_url_hijack crx uninstall_url_hijack=true; monetization/tracking behavior on uninstall redirecting to 3rd party
  • monetization_hits_google_analytics api threat_intel.monetization_hits=[google-analytics.com]; category=AI (not Adblock/Shopping) → Webstore +1.0 telemetry tier
  • ai_extension_processing_page_content store AI/GenAI extension with content_scripts on 20 AI platform origins including chatgpt.com, gemini.google.com → Webstore +2.5
  • free_webmail_no_developer_name store developer_email=mrsoniceman@gmail.com, developer_name=''; free webmail + no business name raises accountability risk

Permissions Breakdown

  • tabs medium Can enumerate open tabs and their URLs; moderate risk for content exfil.
  • storage low Local data persistence; low standalone risk.
  • cookies high Can read/write cookies across origins; paired with *://*/* enables session theft.
  • contextMenus low UI affordance only; low risk.
  • declarativeNetRequest medium Can modify/block network requests declaratively; moderate risk without webRequest.
  • sidePanel low UI surface only; low standalone risk.
  • *://*/* high Broad host access on all URLs; combined with cookies enables cross-site data access.

Pillar Scores

Permissions7.00
Reputation6.50
Network4.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA d380766f7c98…
Force block — not fired
Score recovered no
Elapsed 28.9s