Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Kerra Connect

kbfihlonhdjhlmdpkcfkiflibabpcgag
Risk Score
2.71
Risk Level: Low
Recommendation: ✅ ALLOW
Category Productivity
Installs 392
Rating 5.0
Last updated 2026-08-09
Manifest version MV3
CSP present ✅ yes
Developer support@kerra.work
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Developer name field is empty, reducing accountability signal.
  • No rating count provided; 5-star rating is unverifiable.
  • canvas.columbia.edu in JS external hosts suggests LMS data handling; verify data minimisation.
  • Small install base (392) limits community vetting.
  • localhost/127.0.0.1 in JS external hosts could indicate local companion app; confirm expected behaviour.

Evidence

  • verified_publisher store Extension carries Chrome Web Store verified publisher badge for kerra.work.
  • narrow_host_permissions manifest Host permissions limited to https://kerra.app/* and https://*.kerra.app/*; no broad host access.
  • clean_csp manifest CSP script-src 'self'; object-src 'self' — no remote script sources allowed.
  • no_code_findings crx 0 code findings, obfuscation_score 0.0, 4 JS files scanned — no malicious patterns detected.
  • clean_threat_intel api No bad hosts, monetization hits, affiliate hits, or throwaway domain signals.
  • privacy_policy_complete store Policy fetched, scoped to extension, covers data collection, retention, and third-party sharing.
  • developer_name_missing store developer_name is empty string; reduces attribution and accountability.
  • external_host_lms crx canvas.columbia.edu referenced in JS — LMS integration as described; consistent with stated function.

Permissions Breakdown

  • storage low Standard local data persistence; no cross-origin access.
  • alarms low Scheduled tasks only; no data access.
  • offscreen low Offscreen document for background tasks; low risk in MV3 context.
  • https://kerra.app/* low Narrow host permission scoped to dev-controlled domain only.
  • https://*.kerra.app/* low Wildcard subdomain of dev-controlled kerra.app; still narrow.

Pillar Scores

Permissions0.90
Reputation3.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:20
Listing SHA d1291dfdfea3…
Force block — not fired
Score recovered no
Elapsed