Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screenshot to Notion & Annotate

lkedoimppfegdfhggggbfohioeafkmlp
Risk Score
3.93
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Screenshot
Installs 2,000
Rating 4.8
Last updated 2024-01-24
Manifest version MV3
CSP present ❌ no
Developer support@markuphero.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + <all_urls>: can read session cookies from any site visited.
  • No CSP on MV3 extension; scripting + <all_urls> allows broad page manipulation.
  • Privacy policy fetched but does not scope to this extension or disclose data collection.
  • Last updated 17 months ago; no active maintenance signal.
  • new Function() constructor found in popup.js; limited obfuscation risk but non-zero.

Evidence

  • cookies + <all_urls> manifest cookies permission with <all_urls> host permission enables session theft from any site.
  • no CSP crx content_security_policy is null; no script-src hardening despite scripting + broad hosts.
  • privacy policy inadequate api Policy fetched (1002 chars), scope_extension=false, data_collection=false; too brief, not extension-scoped.
  • verified_publisher + featured store Verified publisher and featured badge; reputation floor applied at 2.0.
  • function_constructor crx new Function() in js/popup.js; likely bundler globalThis shim, low-severity but flagged.
  • stale update store Last updated January 2024 (~17 months); maintenance score +3.5.
  • external JS hosts crx Contacts fonts.googleapis.com, tailwindcss.com, us-central1-markuphero.cloudfunctions.net.
  • no CVEs crx cve_findings_raw empty; no bundled vulnerable libraries detected.

Permissions Breakdown

  • storage low Stores extension settings/data locally.
  • clipboardWrite medium Writes screenshot data to clipboard; medium risk, function-appropriate.
  • activeTab low Scoped to current tab on user action.
  • tabs medium Can read tab URLs/titles across browser; moderate risk.
  • desktopCapture medium Captures screen content; core to screenshot function but sensitive.
  • scripting medium Can inject scripts into pages; paired with <all_urls> increases reach.
  • cookies high Access to cookies on all domains; combined with <all_urls> is high risk.
  • <all_urls> (host_permission) high Broad host access paired with cookies and scripting is highest-risk combo.
  • https://markuphero.com/ low Dev-owned backend for core functionality.
  • https://storage.googleapis.com/ low Google Cloud Storage for asset/image hosting.
  • https://api.notion.com/ low Notion API for stated screenshot-to-Notion feature.

Pillar Scores

Permissions5.10
Reputation2.00
Network2.00
Webstore0.00
Maintenance3.50
Privacy9.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:25
Listing SHA f52dcdfc5df6…
Force block — not fired
Score recovered no
Elapsed 24.6s