Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Шпаргалка VPN

mipkffkddlldacbaljecppmjbejccnli
Risk Score
5.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs
Rating 4.9
Last updated 2026-06-17 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ezagirace763@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission reroutes all browser traffic through developer-controlled infrastructure (skorostvpn.space, RU-hosted).
  • No developer name; free-webmail Gmail address; no verified publisher — identity entirely unverifiable.
  • Privacy policy is Google's own policy (not scoped to this extension) — admits data collection and third-party sharing without extension-specific disclosure.
  • install_url_hijack opens skorostvpn.space on install — undisclosed third-party site, monetization/tracking possible.
  • Extension contacts skorostvpn.space (RU geo), a domain not in host_permissions, raising data-exfil concern for a proxy tool.

Evidence

  • install_url_hijack crx onInstalled opens https://skorostvpn.space/ — third-party RU domain, not disclosed in listing.
  • developer_identity store Developer email ezagirace763@gmail.com (free webmail), no developer name, no verified publisher badge.
  • privacy_policy_generic store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to this extension.
  • proxy_permission manifest proxy declared — can redirect all browser traffic to arbitrary servers controlled by developer.
  • js_external_host_outside_permissions crx skorostvpn.space listed in js_external_hosts but absent from host_permissions — undeclared outbound contact.
  • host_geo_diversity api JS hosts span CA, RU, US — RU-hosted backend for a proxy/VPN raises jurisdiction risk.
  • no_csp manifest content_security_policy is null; MV3 provides some default but no explicit policy declared.
  • cve_findings crx No CVEs detected in bundled libraries; cve_findings_raw empty.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled servers; critical capability for a VPN.
  • https://cloudflare-dns.com/* medium DNS-over-HTTPS lookup host; expected for VPN but adds network reach.
  • https://dns.google/* medium Second DNS-over-HTTPS provider; expected for VPN redundancy.

Pillar Scores

Permissions6.50
Reputation8.00
Network4.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:15
Listing SHA 7db19b2f1ab7…
Force block — not fired
Score recovered no
Elapsed