Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Gold Rush - Slot Machine

kbmindomjiejdikjaagfdbdfpnlanobi
Risk Score
4.42
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 13
Rating
Last updated 2025-09-28 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@top.rodeo
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched from unscoped CDN URL admits data collection and third-party sharing without extension-specific scope — rates maximum privacy score.
  • No developer name listed; anonymous publisher with minimal install base (13 users) raises accountability concern.
  • Privacy policy hosted on cdn.cloudapi.stream (not developer domain top.rodeo) — lacks authenticity and scoping to this extension.
  • Sandbox CSP allows unsafe-inline and unsafe-eval, permitting arbitrary script execution in sandboxed context.
  • 12 distinct external JS hosts referenced in source files, including goo.gl shortener and unrelated third-party domains, indicating broad external surface.

Evidence

  • privacy_policy_generic_cdn crx Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=true, third_party_sharing=true — triggers D hardening +10.0.
  • no_developer_name store developer_name is empty string; no verified publisher badge; anonymous publisher.
  • sandbox_unsafe_eval manifest sandbox CSP includes unsafe-inline and unsafe-eval on script-src; extension_pages CSP is strict.
  • broad_external_hosts crx 12 external JS hosts including goo.gl, bugzilla.mozilla.org, harrytheo.com, mkeystudio.com — 4+ distinct domains.
  • very_low_installs store Only 13 installs; new/obscure extension with no ratings and no operator siblings.
  • cloudapi_stream_host manifest Host permissions include wheel.cloudapi.stream and mines.cloudapi.stream — CDN-style domains not clearly tied to developer domain.
  • maintenance_3_6mo store months_since_update=11; falls in 6-12 month band (+3.5).
  • cve_findings_empty crx No CVEs found; @popperjs/core version unknown; cve_pillar=0.0.

Permissions Breakdown

  • identity low OAuth identity; low risk alone, but paired with googleapis host access it enables user-account linkage.
  • https://www.googleapis.com/* medium Google API host; enables server-side account operations via identity token.
  • https://wheel.cloudapi.stream/* medium Developer-controlled CDN subdomain; unclear purpose beyond stated game function.
  • https://mines.cloudapi.stream/* medium Developer-controlled CDN subdomain; second game endpoint on same opaque CDN.
  • https://top.rodeo/* low Developer's own domain; expected for a game extension.

Pillar Scores

Permissions1.50
Reputation6.50
Network2.00
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:59
Listing SHA bedf5a8ef058…
Force block — not fired
Score recovered no
Elapsed