Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Session Export Tool

mimplmibgdodhkjnclacjofjbgmhogce
Risk Score
5.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 41
Rating
Last updated 2026-02-20 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer vitaliyacloud@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + <all_urls>: can silently read session cookies from any website and export them.
  • clipboardWrite enables cookie/session data exfiltration to clipboard without user confirmation.
  • Privacy policy is Google's generic policy — does not disclose what THIS extension collects.
  • Free-webmail developer (gmail) with no verifiable business identity; unverifiable accountability.
  • Small install count (41) with high-tier permissions is a tail-attack-surface anomaly.

Evidence

  • cookies + <all_urls> manifest Extension declares cookies permission with <all_urls> host access — can exfiltrate any site session.
  • generic privacy policy store Policy URL points to Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free-webmail developer store Developer email vitaliyacloud@gmail.com; no verified business domain or publisher badge.
  • small_install_high_perm api 41 installs with HIGH-tier permissions (cookies+<all_urls>) — install_perm_anomaly flagged.
  • external IP-lookup hosts crx JS contacts api.ipify.org and ifconfig.me to retrieve user IP address — fingerprinting capability.
  • no CSP (MV3) manifest csp_present=false; MV3 provides strict default but no explicit extension page CSP declared.
  • apple.com host permission manifest Specific broad host permission for *.apple.com with no stated Apple-specific functionality.
  • no verified publisher store verified_publisher=false, is_featured_by_google=false; no accountability signals present.

Permissions Breakdown

  • cookies high Can read all cookies across all URLs via <all_urls> host permission — high exfil potential.
  • activeTab low Scoped to user-activated tab only; limited standalone risk.
  • clipboardWrite medium Writes to clipboard; combined with cookies+<all_urls> enables silent session exfil.
  • https://*.apple.com/* medium Specific high-value target host; narrow but notable.
  • <all_urls> high Broad host access amplifies cookies permission — can harvest sessions from any site.

Pillar Scores

Permissions7.00
Reputation7.50
Network4.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:32
Listing SHA 80e1aed76f9f…
Force block — not fired
Score recovered no
Elapsed