Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Briskine: Email templates for Gmail™

lmcngpkjkplipamgflhioabnhnopeabf
Risk Score
4.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 4.5
Last updated 2026-05-20 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@briskine.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: admits broad data sharing without scoping to this extension.
  • Broad host permissions (https://*/*, http://*/*) with scripting allow content injection on every site visited.
  • brand_mention.is_impersonation==true (LinkedIn mentioned) and developer_name is empty; not a verified publisher.
  • Sandbox CSP contains unsafe-eval; DOM-XSS sink (innerHTML) present in content script on all pages.
  • Uninstall URL hijack flagged; no developer name provided in listing.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy score per v3.5 rule D.
  • broad_host_access manifest host_permissions include https://*/* and http://*/*; content_scripts also match both. Full site access.
  • brand_impersonation store brand_mention.is_impersonation=true (LinkedIn), verified_publisher=false, is_featured_by_google=true → +1.0 reputation.
  • dom_xss_sink crx innerHTML assigned from variable in content/content.js; CSP present but sandbox allows unsafe-eval.
  • uninstall_url_hijack crx uninstall_url_hijack=true; uninstall_url_target=null. Triggers +3.0 webstore signal.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty applied.
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount.
  • sandbox_unsafe_eval manifest content_security_policy.sandbox includes unsafe-eval on script-src, elevating XSS risk in sandboxed context.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata across all open tabs.
  • contextMenus low Adds items to right-click menu; low standalone risk.
  • storage low Local data persistence for templates; expected for this category.
  • scripting medium Can inject scripts into pages; medium risk, paired with broad host access.
  • unlimitedStorage low Removes storage quota; low security risk but resource concern.
  • https://*/* high Broad host access to all HTTPS sites enables content reading/injection.
  • http://*/* high Broad host access to all HTTP sites; expands attack surface.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA e8b013acc454…
Force block — not fired
Score recovered no
Elapsed 24.7s