Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GitHub Clone Helper

kfabhahlbkfegapejbcigihbgjnpdobm
Risk Score
5.30
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 54
Rating
Last updated 2023-06-25 (36 months ago)
Manifest version MV3
CSP present ❌ no
Developer eposta@ercanermis.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (D rule: +10.0).
  • Extension last updated June 2023 (36 months ago) — at stale threshold with no active maintenance.
  • Brand impersonation flag: mentions 'github' in name/description with confirmed_owner=false and no verified publisher.
  • No developer name listed; email uses personal domain with no 'Offered by' verification.
  • MV3 no CSP: +2.0 network penalty applied per v2 calibration fix (b).

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
  • brand_impersonation store brand_mention.is_impersonation=true, brands=['github'], confirmed_owner=false, not verified_publisher → +2.0 reputation.
  • maintenance_stale store months_since_update=36; hits 24-36mo band → +8.5 maintenance pillar.
  • no_developer_name manifest developer_name is empty string; no 'Offered by' display → +1.0 reputation.
  • no_csp_mv3 manifest content_security_policy=null on MV3 → +2.0 network per v2 fix (b).
  • code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty → code quality 0.0.
  • no_cve crx cve_findings_raw empty, no bundled libraries detected → CVE pillar 0.0.
  • low_install_count store Only 54 installs; no install anomaly flags set; tail-attack-surface false.

Permissions Breakdown

  • activeTab low Scoped to user-initiated action on current tab only; minimal surface.
  • scripting medium Allows JS injection into pages; paired with activeTab limits scope but still executable.
  • content_scripts: https://github.com/* low Narrow host match; limited to GitHub only, matches stated function.

Pillar Scores

Permissions1.30
Reputation7.00
Network2.00
Webstore2.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA edb2a1933594…
Force block — not fired
Score recovered no
Elapsed 20.8s