Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Anime Cursor - Custom Cursor for Chrome™ - All in One Anime Cursors

kbgpgmcbehkiiooamcldaccehdcdenmn
Risk Score
2.91
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 30,000
Rating 4.1
Last updated 2026-08-11 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host_permissions (*://*/*) + scripting allows content injection on every visited site.
  • Uninstall and install URL hijack redirect users to developer's marketing page.
  • innerHTML DOM-XSS sink in bundled JS (no CSP to mitigate) — exploitation surface if cursor data is attacker-controlled.
  • Developer name missing from listing despite verified publisher badge — accountability gap.
  • No CSP defined (csp_present=false); MV3 strict-default applies but innerHTML findings increase residual XSS risk.

Evidence

  • broad_host_permissions manifest host_permissions and content_scripts_matches both set to *://*/* — runs on every page.
  • uninstall_url_hijack crx setUninstallURL targets gameograf.com marketing page with UTM params.
  • install_url_hijack crx onInstalled opens gameograf.com marketing page with UTM params.
  • dom_sink_innerhtml crx Two JS files contain unguarded innerHTML assignments; no CSP to limit exploitation.
  • verified_publisher_featured store Extension carries both verified_publisher and is_featured_by_google badges — reputation discounts applied.
  • privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
  • no_developer_name store developer_name field is empty despite verified publisher status.
  • js_external_hosts crx Contacts api.gameograf.com, gameograf.com, chrome.google.com, reactjs.org — 4 distinct domains.

Permissions Breakdown

  • storage low Stores user cursor preferences locally; low risk.
  • scripting medium Allows programmatic script injection into pages; elevated risk with broad host access.
  • *://*/*HostPermission high Broad host access to all URLs; enables content injection on every site visited.

Pillar Scores

Permissions4.50
Reputation2.00
Network2.00
Webstore5.00
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 10:36
Listing SHA b95f0c577bc0…
Force block — not fired
Score recovered no
Elapsed