Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Grammarly: AI Writing Assistant and Grammar Checker App

kbfnbcaeplbcioakkpcpgfkobkghlhen
Risk Score
5.25
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 38,000,000
Rating 4.5
Last updated 2026-08-26
Manifest version MV3
CSP present ✅ yes
Developer support@grammarly.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false and admits data_collection+third_party_sharing — generic corporate policy, not extension-scoped (Privacy=10.0).
  • Broad host permissions (http://*/*, https://*/*) combined with cookies permission enables access to session tokens on every site visited.
  • AI writing assistant reads text from all websites including sensitive/confidential content on all 38M installs.
  • Three innerHTML DOM-XSS sinks in production JS — CSP present mitigates but does not eliminate risk from page-content injection.
  • No verified publisher badge and developer_name empty — despite grammarly.com domain, formal publisher verification absent.

Evidence

  • broad_host_permissions manifest http://*/* and https://*/* grant content-script injection on every site; cookies permission amplifies to session-token risk.
  • privacy_policy_not_extension_scoped crx policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (v3.5 rule D).
  • dom_xss_sinks crx 3 innerHTML findings in vendors+inkwell chunks; CSP present (script-src 'self') reduces exploitation path but sinks exist.
  • ai_extension_page_content store AI writing assistant processes text on all visited pages; +2.5 AI webstore signal applied.
  • no_verified_publisher store verified_publisher=false, developer_name empty; is_featured_by_google=true reduces reputation risk partially.
  • cookies_high_perm manifest cookies + <all_urls> host access is HIGH×1.2 multiplier surface.
  • connect_src_broad crx CSP connect-src lists 40+ endpoints including S3, Iterable, Superhuman, CloudFront — diverse external connectivity.
  • react_17_bundled crx React 17.0.2 bundled; no CVEs found in cve_findings_raw, no score impact.

Permissions Breakdown

  • scripting medium Can inject JS into pages; paired with broad host_permissions amplifies risk.
  • sidePanel low UI surface only, low direct risk.
  • tabs medium Access to tab URLs and metadata across all open tabs.
  • notifications low Can display notifications; limited abuse surface.
  • cookies high Read/write cookies; combined with broad host access enables session token access.
  • identity medium OAuth token access; scoped but can expose user identity.
  • storage low Local extension storage only.
  • http://*/* high Broad host permission — content scripts run on all HTTP sites.
  • https://*/* high Broad host permission — content scripts run on all HTTPS sites, including banking/email.

Pillar Scores

Permissions7.50
Reputation3.00
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn0a5fd568dp727562726963xsx 4.42 Medium review 2026-08-30
fsssiedxa"sssiedx 4.66 Medium review 2026-08-07
sssieddrubricxsx 4.73 Medium review 2026-08-07
%76%33%2E%36%39%38%30%39%22%28%29%3B%7D%5D%39%37%30%34 4.87 Medium review 2026-08-05
<%={{={@{#{${dfb}}%> 5.26 Medium review 2026-08-05
v3.6&n973472=v914877 4.92 Medium review 2026-08-05
v3.6 5.25 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA cf81f8a10596…
Force block — not fired
Score recovered no
Elapsed 29.0s