Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Simple Sticky Notes

lkkkngnoflaeicokibjcmgjacmhlnghg
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 9,000
Rating 4.9
Last updated 2026-06-13
Manifest version MV3
CSP present ❌ no
Developer dmi.build1@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no verified business name; no 'Offered by' identity.
  • Privacy policy fetched but scope_extension=false and data_collection=false with length=1 — appears minimal/inadequate.
  • install_url_hijack: onInstalled opens chrome://extensions/shortcuts (unusual redirect on install).
  • uninstall_url_hijack flag set (target null but flag true) — warrants review.
  • scripting + content_scripts on <all_urls> with no CSP allows broad page-script injection on every site.

Evidence

  • free_webmail_dev store Developer email dmi.build1@gmail.com; developer_name empty; no verified business domain.
  • verified_publisher+featured store verified_publisher=true AND is_featured_by_google=true; discounts applied to reputation.
  • install_url_hijack crx install_url_target=chrome://extensions/shortcuts; onInstalled redirects user to shortcuts page.
  • uninstall_url_hijack_flag crx uninstall_url_hijack=true but target is null; flag raised by scanner, no 3rd-party URL confirmed.
  • no_csp manifest content_security_policy=null on MV3 extension with <all_urls> host permission.
  • privacy_policy_inadequate api Policy length=1, scope_extension=false, data_collection=false — too thin to be meaningful.
  • broad_host_with_scripting manifest scripting + content_scripts on <all_urls>; can inject JS into every page the user visits.
  • js_external_hosts crx 5 external hosts: docs.google.com, radix-ui.com, react.dev, simplestickynotes.xyz, www.google.com.

Permissions Breakdown

  • identity low OAuth token access; no broad scopes declared; low standalone risk.
  • activeTab low Transient access to current tab on user action only.
  • scripting medium Programmatic script injection into pages; combined with <all_urls> raises risk.
  • contextMenus low UI surface only; low data-access risk.
  • unlimitedStorage low Allows large local storage; no direct data-exfil vector.
  • alarms low Scheduling only; minimal risk.
  • storage low Local key-value store; expected for a notes app.
  • sidePanel low UI panel; no data-access capability.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • <all_urls> (host_permission) high Content scripts injected into every site; broad reach for a notes app.

Pillar Scores

Permissions6.00
Reputation3.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA 6e63dfb83ae9…
Force block — not fired
Score recovered no
Elapsed 23.5s