Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Online Security

llbcnfanfmjhpedaedhbcnpgeepdnnok
Risk Score
7.27
Risk Level: High
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category Security
Installs 11,000,000
Rating 3.6
Last updated 2026-07-01 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@reasonlabs.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • Privacy policy fetched but scope_extension=false AND admits data_collection+third_party_sharing → privacy pillar 10.0
  • nativeMessaging with unrecognized publisher (+3.0 perm) combined with <all_urls> cookies/browsingData/contentSettings creates critical capability stack
  • management permission can enumerate and disable other security extensions
  • No developer name listed; no verified-publisher badge despite 11M installs

Evidence

  • privacy_policy_scope_extension_false_with_collection_and_sharing api Policy fetched (117k chars) but scope_extension=false, data_collection=true, third_party_sharing=true → privacy score 10.0
  • native_messaging_unrecognized_publisher manifest has_native_messaging=true, publisher_recognized=false — companion app identity unverifiable
  • high_capability_permission_stack manifest cookies+browsingData+contentSettings+management+<all_urls> together represent near-total browser control
  • no_csp_mv3_dom_xss_sinks crx csp_present=false + dom_sink_innerhtml_userctrl in contentScript.bundle.js running on <all_urls>
  • no_developer_name_no_verified_publisher store developer_name empty, verified_publisher=false, is_featured_by_google=true but capability gate applies
  • external_js_hosts crx js_external_hosts: feross.org, www.instagram.com — unexpected for a security tool
  • rating_3_6_at_11m_installs store Rating 3.6 at 11M installs is below threshold; no review red flags flagged but low score notable
  • cve_findings_clean crx cve_findings_raw empty; no CVE exposure detected

Permissions Breakdown

  • storage low Standard local data storage.
  • unlimitedStorage low Extended storage quota; low standalone risk.
  • management high Can enumerate/disable/enable other installed extensions.
  • tabs medium Can read URLs and titles of open tabs.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • downloads medium Can trigger and manage file downloads.
  • downloads.shelf low UI control over downloads shelf only.
  • downloads.open medium Can open downloaded files on disk.
  • notifications low Desktop notifications; low risk alone.
  • webNavigation medium Observes all navigation events across tabs.
  • contextMenus low Adds right-click menu items.
  • contentSettings high Can override per-site JS/plugin/cookie settings globally.
  • browsingData high Can delete history, cookies, cache across all sites.
  • history medium Full read/write access to browsing history.
  • nativeMessaging high IPC with a native app; publisher not recognized — high risk.
  • idle low Detects user idle state only.
  • alarms low Scheduled background tasks.
  • cookies high Read/write cookies for all origins via <all_urls>.
  • <all_urls> (host) high Content scripts injected into every site; full data access.

Pillar Scores

Permissions8.50
Reputation5.50
Network3.50
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn47a001efdp727562726963xsx 6.11 High block 2026-09-09
<fsssiedx{'sssiedx 6.14 High block 2026-08-22
%22fsssiedxt$'sssiedx 6.16 High block 2026-08-22
&#x22;fsssiedxt sssiedx 6.36 High block 2026-08-22
<fsssiedxf$"sssiedx 6.36 High block 2026-08-22
<fsssiedxi$"sssiedx 6.24 High block 2026-08-22
<fsssiedxa$"sssiedx 6.21 High block 2026-08-22
dfb[[${98991*97996}]]xca 6.18 High block 2026-08-07
v3.6&n921894=v994239 6.24 High block 2026-08-07
dfb{{98991*97996}}xca 6.24 High block 2026-08-05
bfgx6119%C0%BEz1%C0%BCz2a%90bcxhjl6119 6.12 High block 2026-08-05
v3.6&n948590=v915138 6.21 High block 2026-08-05
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%51%68%59%72%28%39%32%30%37%34%29%22 5.77 Medium block 2026-08-04
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 6.02 High block 2026-08-04
<th:t="${dfb}#foreach 5.97 Medium block 2026-08-04
v3.6&n987420=v970270 6.23 High block 2026-08-04
<fsssiedx{&#x27;sssiedx 6.15 High block 2026-07-30
<fsssiedx{$"sssiedx 6.09 High block 2026-07-30
<fsssiedx{ xx psssiedx 5.48 Medium block 2026-07-30
<fsssiedx{ 6.34 High block 2026-07-30
fsssiedx<sssiedx 6.01 High block 2026-07-30
fsssiedxdsssiedx 6.09 High block 2026-07-30
fsssiedxd'sssiedx 6.29 High block 2026-07-30
fsssiedxd 6.07 High block 2026-07-30
sssieddrubricxsx 6.17 High block 2026-07-30
v3.6'"()&%<zzz><ScRiPt >5TFt(9385)</ScRiPt> 6.23 High block 2026-07-29
v3.6&n916810=v997204 6.38 High block 2026-07-29
v3.6 7.27 High block 2026-06-16
v3.4-rev 5.07 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA e228f9688881…
Force block 🚫 fired
Score recovered no
Elapsed 29.6s