Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Discord Batch Deleter

lgmnomldfahgdpkbmlegninjpokgmoob
Risk Score
6.43
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 3,000
Rating 3.1
Last updated 2024-08-30 (22 months ago)
Manifest version MV3
CSP present ✅ yes
Developer hhhust@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • importScripts loads remote code from storage.googleapis.com — runtime code injection risk in service worker.
  • Brand impersonation: 'Discord' in name, dev is gmail user with no confirmed ownership.
  • CSP connect-src includes doubleclick.net and Google Tag Manager — ad-tech in a message-deletion tool is anomalous.
  • Privacy policy scoped to slackext.com, not this extension; no data-collection or retention disclosure.
  • Uninstall URL hijack present; content script runs on all discord.com pages with innerHTML sinks.

Evidence

  • import_scripts_remote crx service-worker.js calls importScripts('https://storage.googleapis.com/workbox-cdn/...') — remote code load.
  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, dev email hhhust@gmail.com, no dev name.
  • monetization_hosts_in_csp manifest connect-src includes doubleclick.net, ssl.google-analytics.com, googletagmanager.com — ad-tech in productivity tool.
  • uninstall_url_hijack crx uninstall_url_hijack=true — extension registers uninstall redirect to third party.
  • privacy_policy_not_scoped api Policy fetched but scope_extension=false, data_collection=false; generic slackext.com page, 711 chars.
  • free_webmail_no_dev_name store developer_name empty, developer_email hhhust@gmail.com — no verified business identity.
  • stale_22mo store Last updated Aug 2024, 22 months ago — approaching zombie threshold with known code risks.
  • verified_publisher_flagged store verified_publisher=true but monetization_hits non-empty (doubleclick.net) — discount capped at -1.0 per v3.5(E).

Permissions Breakdown

  • storage low Local key-value store; no cross-origin data exposure.
  • activeTab low Scoped to user-activated tab only; limited reach.
  • host_permission: https://slackext.com/ medium Allows direct network access to developer-controlled backend; exfil vector.
  • content_scripts: https://*.discord.com/* medium Injects JS into all Discord pages; reads messages and tokens in context.

Pillar Scores

Permissions2.60
Reputation7.50
Network5.50
Webstore6.50
Maintenance6.00
Privacy9.00
Code Quality7.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA 4de2eca78181…
Force block — not fired
Score recovered no
Elapsed 44.0s