Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Black Script

lmenhcepphonnfnjkaofobpamlfolgfl
Risk Score
4.63
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 104
Rating 5.0
Last updated 2026-03-25 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer qsakaro@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope to this extension, admits data collection and third-party sharing (privacy pillar capped at 10).
  • Free-webmail developer (qsakaro@gmail.com) with no developer name or verified identity — elevated reputation risk.
  • Extension contacts external hosts (example.com, forms.gle, t.me) with no CSP; destination purpose unclear.
  • Very low install base (104) with external JS hosts creates a tail attack surface if extension is ever compromised.
  • No developer name provided, raising accountability concerns for enterprise deployment.

Evidence

  • generic_privacy_policy store Privacy policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true — maps to +10 Privacy per v3.5 rule D.
  • free_webmail_no_dev_name store Developer email qsakaro@gmail.com; developer_name is empty. Reputation start 5 +1.5 (free webmail, no biz site) +1.0 (no dev name) = 7.5 floor applied.
  • external_js_hosts crx js_external_hosts: example.com, forms.gle, t.me — 3 distinct domains referenced from JS; no CSP present.
  • narrow_content_script manifest Content script scoped only to https://forum.blackrussia.online/* — single-site forum helper, low capability.
  • no_csp_mv3 manifest csp_present=false; MV3 default is strict, so no +2 Network penalty applies, but no mitigating CSP either.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; jquery 3.7.1 bundled (no known CVEs).
  • low_install_count store 104 installs; not a broad-reach risk but limits trust signals.
  • no_bad_hosts_no_monetization api threat_intel.bad_host_hits, monetization_hits, affiliate_hits all empty; no threat-intel risk amplifiers.

Permissions Breakdown

  • storage low Stores local settings; no cross-site or data-exfil capability on its own.
  • content_scripts: https://forum.blackrussia.online/* medium Runs JS on a single specific forum domain; narrow but grants DOM access on that origin.

Pillar Scores

Permissions1.00
Reputation7.50
Network0.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:18
Listing SHA 32b369ce9b51…
Force block — not fired
Score recovered no
Elapsed