Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Adapt - Find Emails On Websites

lbhigcppinlecjbkgkaapkfekijdndaj
Risk Score
3.76
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 30,000
Rating 4.6
Last updated 2025-09-05 (9 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@adapt.io
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — triggers +10.0 privacy pillar (v3.5 rule D).
  • No developer display name in listing; only email identity available.
  • Content script on LinkedIn can read profile/contact data; extension's stated function is email harvesting.
  • Extension is 9 months stale (+3.5 maintenance); not critical but worth monitoring.
  • CSP present and scoped; MV3; no code findings — technical posture is clean.

Evidence

  • privacy_policy_classification api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
  • permissions manifest tabs(medium)+storage(low)+system.display(low)+host LinkedIn+adapt.io. No HIGH-tier permissions.
  • reputation store No developer display name (+1.0). is_featured_by_google=true (-2.0). No verified publisher badge. Base 5+1-2=4; floor 2 → 4.0 before org check.
  • reputation_featured store is_featured_by_google=true applied -2.0 discount on reputation pillar.
  • maintenance store 9 months since update → 6-12 month band = +3.5.
  • network_behavior crx CSP present, MV3, no unsafe-eval/inline. js_external_hosts include adapt.io subdomains+Google+LinkedIn — all scope-aligned. geo=2 countries.
  • code_quality crx code_findings_raw empty, obfuscation_score=0.0, no JS libraries detected. Score=0.0.
  • threat_intel api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], domain resolves, not throwaway.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; moderate sensitivity.
  • storage low Local extension data storage only.
  • system.display low Read display configuration; minimal data risk.
  • https://*.adapt.io/ low Scoped to developer's own domain only.
  • https://www.linkedin.com/ medium Content script on LinkedIn; can read page data including profile info.

Pillar Scores

Permissions2.30
Reputation5.00
Network1.50
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA 386a90f595e0…
Force block — not fired
Score recovered no
Elapsed 22.5s