Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GPTZero: AI Detection & Writing Replay

kgobeoibakoahbfnlficpmibdbkdchap
Risk Score
5.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 400,000
Rating 4.7
Last updated 2026-06-16
Manifest version MV3
CSP present ❌ no
Developer team@gptzero.me
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true — admits broad data sharing without scoping to extension (v3.5 D: +10.0 privacy).
  • Content scripts on <all_urls> combined with cookies permission enables reading page content and session cookies across all sites including Google Docs and ChatGPT.
  • 10 innerHTML DOM-XSS sinks across multiple content-script files with no CSP; elevated DOM-XSS risk per FIX B.
  • brand_mention.is_impersonation=true (mentions Google brand) without verified_publisher — reputation penalty applied.
  • Uninstall URL hijack detected (uninstall_url_hijack=true); third-party destination unconfirmed — webstore penalty applied.

Evidence

  • privacy_policy_scope_extension_false_with_data_and_third_party_sharing api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
  • content_scripts_all_urls_plus_cookies manifest content_scripts matches <all_urls>; cookies permission allows reading cookies on all host_permission domains.
  • dom_sink_innerhtml_no_csp crx 10 innerHTML sinks across content scripts; csp_present=false triggers FIX B elevated scoring (+2.0 code quality).
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() to third-party target detected; +3.0 webstore penalty.
  • brand_impersonation_google store brand_mention.is_impersonation=true, Google mentioned; not verified_publisher, not featured for this signal.
  • ai_extension_page_content store AI detection category processing page content on Google Docs/ChatGPT; +2.5 webstore AI signal.
  • no_csp_mv3 manifest content_security_policy=null on MV3; MV3 strict default applies, no +2.0 network penalty for missing CSP.
  • is_featured_by_google store Extension carries Google Featured badge; -2.0 reputation discount applied.

Permissions Breakdown

  • scripting medium Can inject scripts into pages; broad reach given content_scripts on <all_urls>.
  • cookies high Access to cookies across host_permissions scope including Google Docs, ChatGPT.
  • storage low Local extension storage only.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • tabs medium Can read tab URLs and titles across browser.
  • alarms low Scheduled background tasks; low risk alone.
  • host:<all_urls> (content_scripts) high Content scripts run on all URLs — broad page-content read access.
  • host:https://*.gptzero.me/* low Developer's own domain; expected for AI detection service.
  • host:https://docs.google.com/* medium Access to Google Docs content — sensitive documents.
  • host:https://chatgpt.com/* medium Access to ChatGPT sessions and conversation content.
  • host:https://*.growthbook.io/* medium Third-party A/B testing/feature-flag service; data may flow externally.
  • host:http://localhost/* low Localhost access; likely dev/staging only.

Pillar Scores

Permissions6.50
Reputation5.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA 951d9e0bd5f8…
Force block — not fired
Score recovered no
Elapsed 36.2s