Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Asana

khnpeclbnipcdacdkhejifenadikeghk
Risk Score
4.02
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 3.2
Last updated 2024-08-02 (22 months ago)
Manifest version MV3
CSP present ❌ no
Developer apps-external@asana.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy not scoped to this extension; admits data collection and third-party sharing without extension-specific disclosure (+10.0 privacy).
  • Dynamic script injection in sidebar.js and background_bundle.js could load remote code at runtime (script_src_dynamic).
  • Content script on Gmail (mail.google.com) gives access to email content — high-sensitivity surface.
  • Extension last updated 22 months ago; no security patches for nearly 2 years.
  • No CSP declared (MV3 so no v2 penalty, but dynamic script creation without CSP raises runtime trust boundary concerns).

Evidence

  • verified_publisher + featured store Asana is a verified publisher and Google-featured extension; reputation floor capped at 2.0.
  • privacy_policy_scope_miss api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule applies: +10.0 privacy.
  • script_src_dynamic x2 crx Dynamic <script> creation found in sidebar.js and background_bundle.js; no CSP to constrain destination.
  • gmail_content_script manifest Content script injected into mail.google.com — can observe and modify email DOM.
  • stale_extension store 22 months since last update; maintenance score +6.0 (6-24mo band).
  • no_csp manifest content_security_policy is null; MV3 default applies but dynamic script findings add risk.
  • js_external_hosts crx js_external_hosts includes www.example.com — placeholder or test artifact; low impact but noteworthy.
  • threat_intel_clean api No bad_host_hits, monetization_hits, or affiliate_hits; developer domain resolves; sibling_count=0.

Permissions Breakdown

  • cookies high Can read/write cookies; scoped only to asana.com and mail.google.com by host_permissions.
  • activeTab low Transient access to current tab on user gesture only.
  • scripting medium Can inject scripts; scoped to declared host permissions.
  • storage low Local extension storage only, no cross-site exfil risk by itself.
  • contextMenus low UI integration only, no data access.
  • tabs medium Can read tab URLs and titles across all tabs.
  • clipboardWrite medium Can write to clipboard; no read capability declared.
  • https://*.asana.com/* medium Broad subdomain access scoped to first-party Asana domain.
  • https://mail.google.com/* high Content script injected into Gmail; can read email content and interact with mail UI.

Pillar Scores

Permissions4.50
Reputation2.00
Network3.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality3.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA 6b0c5967c690…
Force block — not fired
Score recovered no
Elapsed