Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Adobe Photoshop

kjchkpkjpiloipaonppkmepcbhcncedo
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 800,000
Rating 3.8
Last updated 2026-08-25
Manifest version MV3
CSP present ✅ yes
Developer chrome-support@adobe.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack declared; redirects user to unknown 3rd-party page on removal.
  • No developer name listed despite high-profile Adobe branding — unverifiable publisher identity.
  • Privacy policy fetch failed (ReadTimeout); effective privacy posture is unknown, scored worst-case.
  • Content scripts on <all_urls> give broad page-read capability across all 800K users' browsing.
  • chatgpt.com and github.com listed as JS external hosts — unexpected for a Photoshop imaging extension.

Evidence

  • uninstall_url_hijack crx uninstall_url_hijack=true; target=null. Extension registers an uninstall redirect to a 3rd-party URL. Webstore +3.0.
  • privacy_policy_fetch_failed crx privacy_policy_classification.fetched=false (ReadTimeout). Privacy pillar scored at maximum 10.0.
  • no_developer_name store developer_name is empty string. Reputation +1.0 (no Offered By name).
  • not_verified_publisher store verified_publisher=false for an extension claiming Adobe branding. No -3.0 verified discount.
  • is_featured_by_google store is_featured_by_google=true. Reputation -2.0 featured discount applied.
  • broad_host_permissions_and_content_scripts manifest host_permissions and content_scripts_matches both set to <all_urls>; runs on every site.
  • unexpected_external_hosts crx js_external_hosts includes chatgpt.com, github.com, wxt.dev alongside adobe.com endpoints.
  • ai_extension_page_content store Category AI + content scripts on <all_urls>; Webstore +2.5 AI/GenAI signal applied.

Permissions Breakdown

  • storage low Local data persistence; low standalone risk.
  • tabs medium Can read tab URLs and titles; moderate privacy surface.
  • contextMenus low UI integration only; low risk.
  • sidePanel low UI panel display; low risk.
  • declarativeNetRequest medium Can redirect/block network requests without seeing content; moderate risk.
  • <all_urls> (host_permissions) high Broad host access enables content-script injection on every site visited.
  • <all_urls> (content_scripts_matches) high Scripts run on every page; high data-access reach amplified by <all_urls>.

Pillar Scores

Permissions6.50
Reputation4.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 13:52
Listing SHA 53bdc05fa433…
Force block — not fired
Score recovered no
Elapsed