Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Lightshot (screenshot tool)

mbniclmhobmnbdlbpiphghaielnnpgdp
Risk Score
5.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 2,000,000
Rating 4.4
Last updated 2024-07-22 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@skillbrains.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + *://*/* host permission: full cookie exfil capability if compromised.
  • Privacy policy fetched but admits data collection and 3rd-party sharing without extension-specific scope.
  • jquery@3.2.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP to mitigate XSS.
  • Extension not updated in 23 months; approaching stale threshold with live CVEs.
  • No developer display name; 10 external JS hosts including social networks beyond screenshot function.

Evidence

  • cookies + *://*/* host perm manifest cookies permission paired with broad host access enables full cookie read/write on all sites.
  • privacy policy scope mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic, not scoped to extension.
  • jquery@3.2.1 CVEs crx 3 medium-severity XSS CVEs; fixed_in 3.5.0 not applied. No CSP to limit exploitation surface.
  • no CSP + MV3 manifest content_security_policy is empty; MV3 default applies but jquery CVEs remain unmitigated.
  • maintenance: 23 months store Last updated July 2024; 23 months since update with known unpatched CVEs.
  • 10 external JS hosts crx Hosts include api.prntscr.com, upload.prntscr.com, plus social networks (vk.com, facebook.com, twitter.com, pinterest.com).
  • description_promise mismatch store Promises recording but lacks tabCapture/desktopCapture permission — minor mismatch.
  • verified_publisher true store skillbrains.com resolves; verified publisher; domain not throwaway. Reputation floor applied.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • activeTab low Scoped to user-initiated action; expected for screenshot tool.
  • storage low Standard settings/state persistence.
  • unlimitedStorage low Plausible for local screenshot cache.
  • notifications low Low-impact; used for capture confirmations.
  • clipboardWrite medium Can write arbitrary content to clipboard; expected for screenshot copy.
  • downloads medium Can save files to disk; expected for screenshot save.
  • cookies high Full cookie access; combined with *://*/* host perm this is high-risk.
  • *://*/* high Broad host access across all sites; amplifies cookies risk.

Pillar Scores

Permissions5.50
Reputation3.50
Network4.50
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Scoring History

sssiedn2e9d9c9edp727562726963xsx 5.05 Medium review 2026-09-06
<fsssiedx{'sssiedx 5.17 Medium review 2026-07-30
<fsssiedx{$"sssiedx 5.36 Medium review 2026-07-30
<fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx 5.32 Medium review 2026-07-30
<fsssiedx{ 5.35 Medium review 2026-07-30
fsssiedx<sssiedx 5.08 Medium review 2026-07-30
fsssiedxd"sssiedx 5.21 Medium review 2026-07-30
fsssiedxd 4.97 Medium review 2026-07-30
sssieddrubricxsx 5.42 Medium review 2026-07-30
v3.6 5.28 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA fff714085990…
Force block — not fired
Score recovered no
Elapsed 26.6s