Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Search-AI(uses ChatGPT)

mfdccaleigiijoeendegflojjddjhbla
Risk Score
6.72
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category AI
Installs
Rating
Last updated 2023-09-05 (35 months ago)
Manifest version MV3
CSP present ❌ no
Developer parthbhatnagar40@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • ChatGPT brand impersonation by unverified gmail developer with no confirmed ownership.
  • Privacy policy is Google's own account policy — not scoped to this extension at all; admits 3rd-party sharing.
  • Content script injected on all HTTPS sites despite no declared permissions — broad passive reach.
  • Extension last updated 35 months ago; effectively abandoned with broad host content-script surface.
  • Shell pattern flagged: description_promise.is_shell_pattern=true with minimal code surface (1 JS file, no findings).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'chatgpt'; developer is unverified gmail user, confirmed_owner=false.
  • privacy_policy_generic api Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • content_script_broad_host manifest content_scripts_matches=["https://*/*"] injects into all HTTPS pages; no declared permissions[] but effective broad reach.
  • stale_extension store months_since_update=35; last updated Sep 2023. Near 36-month zombie threshold.
  • free_webmail_developer store Developer email parthbhatnagar40@gmail.com; no business domain; developer_name='Parth' only.
  • shell_pattern crx description_promise.is_shell_pattern=true; 1 JS file, obfuscation_score=0, code_findings_raw empty.
  • external_host_openai crx js_external_hosts=["api.openai.com"]; single external host, no bad-host or monetization hits.
  • no_csp manifest content_security_policy=null; csp_present=false on MV3 extension with external API calls.

Permissions Breakdown

  • content_scripts: https://*/* high Content script injected on all HTTPS sites — reads/modifies page content universally.

Pillar Scores

Permissions5.50
Reputation8.00
Network2.00
Webstore7.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 09:14
Listing SHA 391fe5a2a92b…
Force block — not fired
Score recovered no
Elapsed