Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shortcut Assistant

kmdlofehocppnlkpokdbiaalcelhedef
Risk Score
7.64
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs 3
Rating 5.0
Last updated 2026-07-17 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer hello@voidworks.io
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVEs in bundled lodash and underscore 1.8.3 (Prototype Pollution, Arbitrary Code Execution) with no CSP on MV3.
  • Multiple high-severity CVEs in lodash, nth-check, css-what, underscore — versions unknown/unfixed.
  • Dev-operated DigitalOcean proxy (proxy-zcffd.ondigitalocean.app) receives extension traffic; server-side handling opaque.
  • lodash is a DOM-manipulation-adjacent lib with critical/high CVEs and no CSP: CVE amplifier applies.
  • Developer name absent from store listing; only 3 installs reduces trust signal despite verified publisher badge.

Evidence

  • critical_cve_lodash crx CVE-2019-10744 (critical Prototype Pollution) and CVE-2021-23337 (high Command Injection) in bundled lodash@unknown.
  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical Arbitrary Code Execution); fixed_in 1.12.1.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening, amplifying CVE risk.
  • dev_proxy_endpoint manifest host_permissions include https://proxy-zcffd.ondigitalocean.app/* — dev-operated proxy with unknown server-side data handling.
  • verified_publisher store Extension has verified_publisher=true with matching dev domain voidworks.io that resolves.
  • privacy_policy_adequate api Privacy policy fetched, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true, third_party_silence=false.
  • telemetry_only_monetization crx threat_intel.monetization_hits contains only Google Analytics; no affiliate or bad-host hits.
  • narrow_content_script manifest content_scripts scoped to https://app.shortcut.com/* only; matches stated function as Shortcut power-user tool.

CVE Exposures (13)

CVELibrarySeverity Fixed inSummary
CVE-2026-41907 uuid@unknown moderate 11.1.1 uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41988 uuid@unknown moderate 11.1.1 uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2021-3803 nth-check@unknown high 2.0.1 Inefficient Regular Expression Complexity in nth-check
CVE-2022-21222 css-what@unknown high 2.1.3 css-what vulnerable to ReDoS due to use of insecure regular expression
CVE-2021-23337 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2026-4800 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2018-16487 lodash@unknown high 4.17.11 Prototype Pollution in lodash
CVE-2025-13465 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2026-2950 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2018-3721 lodash@unknown moderate 4.17.5 Prototype Pollution in lodash
CVE-2019-10744 lodash@unknown critical 4.17.12 Prototype Pollution in lodash
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab low Accesses current tab only on user action; low ambient risk.
  • commands low Registers keyboard shortcuts; no data access.
  • identity low OAuth token flow; no broad scope declared.
  • storage low Local/sync storage only; no exfil path alone.
  • tabs medium Can enumerate tab URLs/titles; mild privacy surface.
  • https://api.openai.com/* medium Sends content to OpenAI API; data leaves browser.
  • https://proxy-zcffd.ondigitalocean.app/* medium Dev-operated proxy on DigitalOcean; unknown server-side handling.
  • https://www.googleapis.com/* low Standard Google API access; broad but common for identity/AI extensions.
  • content_scripts: https://app.shortcut.com/* low Narrow scope to single SaaS app; matches stated purpose.

Pillar Scores

Permissions2.50
Reputation3.00
Network3.50
Webstore1.50
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure9.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:00
Listing SHA 5f4e04b7f722…
Force block — not fired
Score recovered no
Elapsed