Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Save Story for Instagram

lknpbgnookklokdjomiildnlalffjmma
Risk Score
4.58
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 100,000
Rating 4.3
Last updated 2026-08-12 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer lisap6237@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail dev email + free hosting privacy policy + Instagram brand impersonation raises unverifiable identity risk.
  • scripting + <all_urls> content_scripts grants arbitrary JS injection on every site visited, not just Instagram.
  • new Function() constructor in bg.js enables dynamic code execution from potentially user/network-controlled input.
  • Privacy policy on Google Sites lacks retention disclosure and third-party sharing silence is unresolved.
  • Instagram brand mention with unconfirmed ownership (confirmed_owner=false) meets impersonation criteria.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is gmail user, not Meta/Instagram.
  • free_webmail_dev store developer_email=lisap6237@gmail.com; free-webmail with no verified business domain.
  • broad_host_access manifest host_permissions=[<all_urls>] + content_scripts_matches=[<all_urls>]; scope far exceeds instagram.com.
  • function_constructor crx new Function() in js/bg.js allows dynamic code execution; risky with <all_urls> content access.
  • privacy_policy_gaps api Policy on sites.google.com; scope_extension=true, data_collection=true, retention=false, third_party_silence=true.
  • featured_by_google store is_featured_by_google=true provides partial legitimacy signal despite other risk factors.
  • js_external_hosts crx References popper.js.org, sweetalert2.github.io, stuk.github.io, www.facebook.com, www.instagram.com.
  • no_csp manifest content_security_policy=null on MV3; MV3 provides strict default but no custom CSP declared.

Permissions Breakdown

  • system.display low Read display configuration; low standalone risk.
  • declarativeNetRequest medium Can block/modify network requests; paired with <all_urls> increases risk.
  • downloads medium Initiates file downloads; core to stated function but abusable.
  • scripting high Injects scripts into pages; combined with <all_urls> gives broad code execution.
  • storage low Local extension data storage; low risk alone.
  • tabs medium Can read tab URLs and navigate; moderate privacy surface.
  • <all_urls> (host_permission) high Content scripts + scripting on all URLs; broad access beyond Instagram alone.

Pillar Scores

Permissions6.50
Reputation7.00
Network2.00
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00

Scoring History

sssiedna83e552bdp727562726963xsx 4.05 Medium review 2026-09-10
v3.6 4.58 Medium review 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:56
Listing SHA f128e71c09da…
Force block — not fired
Score recovered no
Elapsed