Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Slack PWA

llnpadfplnebjlenlkkjfblppjeakoja
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 2,000
Rating 4.8
Last updated 2026-04-16 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer anshu@frimware.in
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension claims to be 'Slack PWA' but developer is unrelated third party (frimware.in).
  • Developer domain does not resolve (frimware.in), raising abandonment/hijack risk.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Extension loads from raw.githubusercontent.com, enabling remote code delivery outside Chrome Web Store review.
  • No developer name listed; verified publisher badge does not offset impersonation + non-resolving domain.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; mentions 'slack' but confirmed_owner=false; developer domain frimware.in is unrelated.
  • developer_domain_not_resolving api threat_intel.developer_domain_info.resolves=false for frimware.in; domain cannot be verified as active.
  • generic_privacy_policy store Privacy policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true); not scoped to extension.
  • remote_js_host crx js_external_hosts includes raw.githubusercontent.com; potential for remote code delivery not reviewed by Web Store.
  • no_csp manifest content_security_policy=null on MV3; default MV3 CSP applies but external host in fingerprint is concerning.
  • verified_publisher_cap_applies store verified_publisher=true but developer_domain_info.resolves=false; v3.5 invariant 0c caps discount at -1.0.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity visible to users.
  • scripting_plus_slack_host manifest scripting permission + content_scripts on app.slack.com/* enables full read/write of Slack sessions.

Permissions Breakdown

  • offscreen low Creates offscreen documents; limited scope, low standalone risk.
  • scripting medium Can inject scripts into pages; scoped to app.slack.com but enables code execution.
  • *://app.slack.com/* medium Host access to Slack app; scoped to single domain but can read/modify all Slack content.

Pillar Scores

Permissions2.30
Reputation7.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA e642c352a32d…
Force block — not fired
Score recovered no
Elapsed 20.7s