Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Visual Debug - feedback collection tool

kihnobiijiigaopmckagnbabbemopjff
Risk Score
5.15
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 193
Rating 5.0
Last updated 2025-10-06 (8 months ago)
Manifest version MV3
CSP present ✅ yes
Developer extensions@promotino.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true — worst-case privacy disclosure.
  • <all_urls> host permission + scripting allows code injection into every site the user visits.
  • function_constructor (new Function) pattern in 4 JS files — dynamic code execution risk.
  • innerHTML assignment from variable in content script — DOM-XSS sink on all sites.
  • Uninstall URL hijack detected and developer_name is empty — reduced accountability.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (v3.5 rule D).
  • broad_host_plus_scripting manifest <all_urls> + scripting permission; extension can inject JS into any site.
  • uninstall_url_hijack crx uninstall_url_hijack=true; +3.0 webstore signal per rubric.
  • function_constructor_multiple_files crx new Function() pattern in background.js, popup.js, issue-preview.js, issue.js — +2.5 code quality.
  • dom_xss_sink crx innerHTML from variable in content.js; CSP present but cve_findings empty — +0.5 code quality.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty.
  • small_install_high_perm api install_perm_anomaly.small_install_high_perm=true; 193 installs with HIGH-tier permissions.
  • featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied.

Permissions Breakdown

  • storage low Stores local extension data; low standalone risk.
  • activeTab medium Access to current tab on user action; moderate scope.
  • tabs medium Can read tab URLs and metadata across sessions.
  • scripting high Can inject scripts into pages; paired with <all_urls> elevates risk.
  • contextMenus low Adds right-click menu items; low risk.
  • <all_urls> high Broad host access enabling scripting on every site the user visits.

Pillar Scores

Permissions5.50
Reputation6.00
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA cc45ed1a9085…
Force block — not fired
Score recovered no
Elapsed 25.8s