Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

intentleads - Engagement based LinkedIn Leads PREVIEW

kjidkkncdchjnnfpclneimlcmghcfoon
Risk Score
3.04
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 40
Rating 5.0
Last updated 2026-02-14 (6 months ago)
Manifest version MV3
CSP present ✅ yes
Developer chrismeinl98@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no business developer name raises accountability concerns.
  • Brand impersonation flag: mentions LinkedIn but developer is not affiliated with LinkedIn.
  • webRequest on LinkedIn can observe all profile/feed network traffic including sensitive data.
  • Small install base (40) with HIGH-tier permission (webRequest) is a tail-attack-surface signal.
  • Privacy policy third_party_silence=true: third-party sharing not explicitly addressed.

Evidence

  • free_webmail_dev store Developer email chrismeinl98@gmail.com; no verified business name listed.
  • brand_impersonation store LinkedIn mentioned in title/description; developer domain gmail.com, confirmed_owner=false, is_impersonation=true.
  • verified_publisher store verified_publisher=true; applies -3.0 reputation discount capped at floor 2.0 per free-webmail rule.
  • install_perm_anomaly api 40 installs with webRequest (HIGH-tier); small_install_high_perm=true.
  • privacy_third_party_silence api privacy_policy_classification.third_party_silence=true; third-party sharing not addressed.
  • clean_code crx code_findings_raw empty, obfuscation_score=0.0, cve_findings_raw empty; no malicious signals.
  • host_scope_narrow manifest Host permissions limited to *://*.linkedin.com/*; not broad cross-site.
  • maintenance_3_to_6_months store months_since_update=6; boundary of 3-6mo band, +1.5 applied.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction; limited blast radius.
  • webRequest high Can observe all network requests on matched hosts; significant surveillance capability.
  • storage low Local data persistence; low direct risk.
  • tabs medium Can read tab URLs and titles; metadata exposure risk.
  • unlimitedStorage low Allows large local storage; no direct exfil risk.
  • *://*.linkedin.com/* medium Broad host access scoped to LinkedIn only; justified by stated function.

Pillar Scores

Permissions4.50
Reputation7.00
Network0.00
Webstore5.00
Maintenance1.50
Privacy1.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:12
Listing SHA e2ab12fc4ef4…
Force block — not fired
Score recovered no
Elapsed