Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pirat Slot

kbnkkecifeppobnemkielnpagifkobki
Risk Score
5.12
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs
Rating
Last updated 2025-09-29 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer viktornadiezhdin@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • <all_urls> host permission grants read/write to every page visited; severely over-permissioned for a slot game.
  • Privacy policy hosted on cdn.cloudapi.stream not scoped to this extension; admits third-party sharing without context.
  • free-webmail dev (gmail) with no developer name raises accountability gap.
  • new Function() constructor in 3 JS files enables dynamic code execution risks.
  • MV3 + no CSP means no additional script-source restriction on extension pages.

Evidence

  • host_permissions_all_urls manifest <all_urls> declared alongside sidePanel for a slot-game extension; no content_scripts to justify breadth.
  • free_webmail_dev_no_name store developer_email=viktornadiezhdin@gmail.com, developer_name empty; no verifiable business identity.
  • privacy_policy_unscoped_third_party api Policy fetched; scope_extension=false, data_collection=false, third_party_sharing=true — admits 3P sharing without scope.
  • function_constructor_multiple_files crx new Function() found in background.js, content-sidebar.js, newtab-app.js — dynamic code execution risk.
  • csp_absent manifest content_security_policy is null; MV3 default applies but no explicit restriction on extension pages.
  • third_party_host_permission manifest https://top.rodeo/* host permission; unknown third-party gambling/ad domain, purpose undisclosed.
  • verified_publisher store verified_publisher=true; partial trust credit, but free-webmail and no dev name limit confidence.
  • install_count_missing store No install count available; blast radius unknown, tail_attack_surface possible.

Permissions Breakdown

  • storage low Local key-value storage only; no cross-origin data exposure.
  • sidePanel low Renders UI in side panel; no elevated data access.
  • <all_urls> (host) high Full read/write access to every page the user visits; broad attack surface.
  • https://top.rodeo/* (host) medium Specific third-party domain access; purpose unclear for a slot-game extension.

Pillar Scores

Permissions5.50
Reputation6.50
Network4.00
Webstore3.00
Maintenance3.50
Privacy9.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:01
Listing SHA 14f6dd58d213…
Force block — not fired
Score recovered no
Elapsed