Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Snowflake

mafpmfcccpbjnhfhjnllmmalhifmlcie
Risk Score
1.22
Risk Level: Low
Recommendation: ✅ ALLOW
Category PrivacyTool
Installs 90,000
Rating 4.8
Last updated 2026-06-10
Manifest version MV3
CSP present ✅ yes
Developer frontdesk@torproject.org
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • innerHTML sink in index.js could be exploited for DOM-XSS if input ever comes from untrusted source.
  • Privacy policy hosted on addons.mozilla.org lacks explicit data-retention disclosure.
  • install_url_hijack flagged true; verify onInstalled handler does not open unexpected 3rd-party URLs.
  • js_external_hosts include 7 domains for documentation/reference links; surface area is low-risk but notable.
  • Developer is Tor Project (recognized org) — no impersonation, but not verified publisher on Chrome store.

Evidence

  • recognized_org_developer store Developer domain torproject.org resolves; Tor Project is a well-known privacy org. Reputation floor 2.0 applied.
  • minimal_permissions manifest Only storage and offscreen declared; no host_permissions, no content_scripts. Very low capability surface.
  • csp_present_mv3 manifest CSP restricts connect-src to *.torproject.net and *.freehaven.net only. No unsafe-eval or broad CDN.
  • dom_xss_sink crx index.js: innerHTML assigned from variable. CSP present and no CVEs reduce amplified risk; base +0.5 applied.
  • privacy_policy_retention_missing api Policy fetched, scoped, no data_collection, but retention==false and third_party_silence==true. Score: +1.0+1.0=2.0.
  • install_url_hijack crx install_url_hijack==true but install_url_target==null; cannot confirm malicious destination.
  • no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.
  • recently_updated store months_since_update=0; actively maintained. Maintenance pillar score 0.0.

Permissions Breakdown

  • storage low Persists local settings; no cross-origin data exposure.
  • offscreen low Allows off-screen document; used for WebRTC proxy operations.

Pillar Scores

Permissions0.60
Reputation2.00
Network1.50
Webstore1.00
Maintenance0.00
Privacy2.00
Code Quality0.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA 424ac1a4b2c4…
Force block — not fired
Score recovered no
Elapsed 21.4s