Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AI Chat & Writing Assistant by Wandpen

macmkmchfoclhpbncclinhjflmdkaoom
Risk Score
4.91
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 1,000
Rating 3.6
Last updated 2026-05-07 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer wandpenhq@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — privacy pillar maxes at 10.
  • Free-webmail dev email (gmail) with no developer name listed elevates reputation risk.
  • scripting + <all_urls> content_scripts allow code injection on every visited page.
  • DOM innerHTML sink in chat JS (dom_sink_innerhtml_userctrl) — potential XSS vector.
  • AI extension processes page content and contacts wandpen.com; policy does not disclose retention.

Evidence

  • privacy_policy_admits_collection_third_party_no_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • free_webmail_dev_no_name store developer_email=wandpenhq@gmail.com, developer_name empty; +1.5 reputation (free-webmail) +1.0 (no offered-by).
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; -3.0 reputation, floor 2.0 applied.
  • host_permissions_all_urls_scripting manifest <all_urls> host permission + scripting + content_scripts on all_urls; high capability.
  • dom_sink_innerhtml_userctrl crx innerHTML from variable in chat-SYV3q8Ch.js; CSP present so +0.5 code quality only.
  • ai_extension_page_content store AI/Gen-AI category processing page content +2.5 webstore; install_count=1000 no blast-radius boost.
  • js_external_hosts crx 8 external hosts including wandpen.com, fb.me, radix-ui.com, react.dev; no bad-host hits.
  • no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.

Permissions Breakdown

  • storage low Local data persistence; low direct harm potential.
  • contextMenus low Adds right-click menu items; typical for writing assistant.
  • alarms low Scheduled callbacks; minimal standalone risk.
  • scripting medium Allows dynamic script injection; elevated risk paired with <all_urls>.
  • <all_urls> (host_permission) high Content script runs on every site; broad data access surface.

Pillar Scores

Permissions4.50
Reputation6.00
Network2.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA cba6cc4db723…
Force block — not fired
Score recovered no
Elapsed 24.6s