Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sinceerly

lhokehflammomchbkmpohfeidffnlpmo
Risk Score
2.77
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 1,000
Rating 4.5
Last updated 2026-08-01
Manifest version MV3
CSP present ❌ no
Developer menloparkmidnightoil@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail host access allows content script to read full email body text on mail.google.com.
  • Free-webmail developer (gmail) with no verified publisher status; low accountability.
  • No CSP declared (MV3 default applies but no explicit policy); innerHTML sinks present.
  • Privacy policy lacks data retention disclosure; third-party sharing admitted.
  • Email content routed through unverified Cloudflare Worker proxy before reaching Anthropic API.

Evidence

  • gmail_host_access manifest host_permissions includes https://mail.google.com/* — full Gmail page access.
  • free_webmail_developer store Developer email menloparkmidnightoil@gmail.com; no verified publisher badge.
  • dom_xss_sink crx Two innerHTML sinks in popup.js and content.js; no CSP to mitigate.
  • proxy_endpoint manifest sinceerly-proxy.ben-001.workers.dev is a personal Cloudflare Worker; email data routed through it.
  • privacy_retention_missing api Privacy policy fetched: scope_extension=true, data_collection=true, retention=false, third_party_sharing=true.
  • stripe_endpoints crx js_external_hosts includes api.stripe.com and buy.stripe.com — payment processing expected for SaaS.
  • no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
  • operator_cluster_clean api sibling_count=0; no related extension cluster detected under same fingerprint.

Permissions Breakdown

  • activeTab low Grants access to current tab on user action only; scoped and low-risk.
  • storage low Local data persistence; no cross-origin exfil risk on its own.
  • https://mail.google.com/* medium Host access to Gmail; can read email content in page context.
  • https://sinceerly-proxy.ben-001.workers.dev/* low Developer-controlled proxy; access expected for stated AI function.
  • https://api.anthropic.com/* low Direct API call to Anthropic; expected for AI email rewriting feature.

Pillar Scores

Permissions2.00
Reputation6.50
Network3.50
Webstore2.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:38
Listing SHA 2ec0fd01d02e…
Force block — not fired
Score recovered no
Elapsed