Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Brasilbot

lbcfbjpjhighachiefcllehigodnlokm
Risk Score
4.68
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 2
Rating
Last updated 2026-08-25
Manifest version MV3
CSP present ❌ no
Developer fgpmonteiro@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies permission scoped to WhatsApp Web enables full session token capture from a sensitive messaging platform
  • Privacy policy is Google's own generic policy — does not describe this extension's data collection at all (v3.5 D: +10.0)
  • Free-webmail developer (gmail), no developer name, no verified publisher status raises accountability concerns
  • js_external_hosts load from notiflix.github.io and reactjs.org — no CSP; external script integrity not enforced
  • install_perm_anomaly: 2 installs with high-tier permissions is tail-attack-surface signal

Evidence

  • cookies+WhatsApp host permission manifest cookies permission + host https://web.whatsapp.com/* allows full session cookie read/write on WhatsApp Web.
  • generic Google privacy policy store Policy URL is myaccount.google.com — scope_extension=false, data_collection=true, third_party_sharing=true. Scores +10.0 under v3.5 D.
  • free-webmail developer, no name store developer_email=fgpmonteiro@gmail.com, developer_name empty, no verified publisher badge.
  • external JS hosts, no CSP crx js_external_hosts=[notiflix.github.io, reactjs.org], csp_present=false. Remote CDN without integrity enforcement.
  • install_perm_anomaly api installs=2, small_install_high_perm=true. High permissions for near-zero user base is tail-attack-surface risk.
  • no code findings / obfuscation crx js_files_scanned=0, obfuscation_score=0.0, code_findings_raw empty — CRX surface unverifiable.
  • no bad host / CVE hits api threat_intel.bad_host_hits=[], cve_findings_raw=[] — no known-malicious infrastructure detected.
  • wayback ownership check api wayback_ownership.ownership_changed=false, first_snapshot=null (fetch_error:ReadTimeout). No transfer evidence.

Permissions Breakdown

  • storage low Standard key-value storage, low risk.
  • unlimitedStorage low Allows large local storage; no direct exfil path alone.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • cookies high Can read/write cookies; scoped to whatsapp.com and app.coderlicences.com host permissions.
  • notifications low Can display desktop notifications; limited abuse surface.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • https://web.whatsapp.com/* high Full access to WhatsApp Web session including messages and auth cookies.
  • https://app.coderlicences.com/* medium Access to developer's own licensing endpoint; unknown data practices.

Pillar Scores

Permissions5.30
Reputation7.50
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:18
Listing SHA 644b54d2d6b6…
Force block — not fired
Score recovered no
Elapsed