Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Google Meet ⇔ Slack integration (Glack)

kddjlbegfaiogihndmglihcgommbjmkc
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 455
Rating 4.0
Last updated 2025-02-18 (16 months ago)
Manifest version MV3
CSP present ✅ yes
Developer meetslack3@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing (→ Privacy pillar 10.0).
  • Brand impersonation: extension name and manifest reference both 'Google' and 'Slack' without verified ownership of either brand.
  • Developer is free-webmail (gmail.com) with no verifiable business identity, raising supply-chain risk.
  • innerHTML sink in popup.js is an unmitigated DOM-XSS vector if untrusted data reaches it.
  • 16 months since last update with no disclosed changelog increases stale-code risk.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands=['slack','google']; confirmed_owner=false; dev domain=gmail.com.
  • generic_privacy_policy store Policy is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email meetslack3@gmail.com; no business website; no verified publisher badge.
  • dom_xss_sink crx popup.js: innerHTML assigned from variable 'data' — DOM-XSS if attacker controls input.
  • is_featured_by_google store Extension carries 'Featured' badge — partial reputation credit applied.
  • maintenance_stale store Last updated February 18 2025; months_since_update=16 — 6-12 month band at scoring time.
  • host_permissions_scoped manifest Host access limited to meet.google.com, slack.com, gstatic.com — matches stated integration function.
  • csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self' — no unsafe-eval or remote CDN; MV3 no bonus penalty.

Permissions Breakdown

  • storage low Stores local config; no cross-site data exposure on its own.
  • https://meet.google.com/* medium Content script host; scoped to Meet only, matches stated function.
  • https://slack.com/* medium Host permission to post status to Slack API; matches stated function.
  • https://www.gstatic.com/* low Static Google asset CDN; read-only resource fetch.

Pillar Scores

Permissions1.50
Reputation7.50
Network0.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA 4eec630cb964…
Force block — not fired
Score recovered no
Elapsed 23.0s