Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Notifier for GitHub

lmjdlojahmbbcodnpecnjnmlddbkjhnn
Risk Score
3.89
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 10,000
Rating 4.7
Last updated 2025-06-26 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer sindresorhus@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admits sharing without scoping to this extension.
  • Developer email is free webmail (gmail.com) with no verified business domain; brand_mention flags GitHub impersonation with confirmed_owner=false.
  • Uninstall URL hijack flag set (uninstall_url_hijack=true) though target is null — warrants review.
  • MV3 but no CSP declared; js_external_hosts include github.com and mozilla.org (content fetched at runtime).
  • Extension is featured by Google, partially offsetting reputation concerns, but verified_publisher=false.

Evidence

  • privacy_policy_generic_with_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
  • brand_impersonation_github store brand_mention.is_impersonation=true, confirmed_owner=false, developer on gmail.com; is_featured_by_google=true → +1.0 Reputation.
  • free_webmail_developer store sindresorhus@gmail.com; no verified publisher badge; +1.5 Reputation for free-webmail dev without verified business.
  • uninstall_url_hijack crx uninstall_url_hijack=true but target=null; rubric +3.0 Webstore not fully applied due to null target, treated as partial signal.
  • is_featured_by_google store Featured badge present → -2.0 Reputation discount applied.
  • maintenance_6_12mo store months_since_update=12 (boundary 6–12 months) → +3.5 Maintenance.
  • no_code_findings_no_cve crx code_findings_raw=[], cve_findings_raw=[], obfuscation_score=0.0; Code Quality=0.0.
  • no_csp_mv3 manifest content_security_policy=null on MV3; no v2 penalty (+2.0 Network) since MV3 has strict default; js_external_hosts=[github.com, mozilla.org, developer.mozilla.org].

Permissions Breakdown

  • alarms low Used for periodic polling of GitHub notification count; low capability.
  • storage low Stores user token/settings locally; standard low-risk permission.
  • offscreen low Allows background DOM work without visible tab; low risk given no exfil findings.

Pillar Scores

Permissions0.90
Reputation6.50
Network2.00
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA e24fbf50fcde…
Force block — not fired
Score recovered no
Elapsed 23.7s