Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DeepSeek Assistant: AI Chat, Minibar, SidePanel & Search

mkhdiephfhifcgpmkaaboknnbdpjlneg
Risk Score
6.28
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs 7,000
Rating 4.6
Last updated 2025-03-24 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer linneamarch498@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: gmail dev account claims DeepSeek brand with no confirmed ownership.
  • Uninstall and install URL hijack both active — classic monetization/tracking shell behavior.
  • webRequest + scripting + <all_urls> = full read/modify capability on every site visited.
  • Free-webmail developer (gmail) with no developer name — low accountability, high takeover risk.
  • 17-month-stale extension with HIGH permissions and verified-publisher cap triggered (0c).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer domain is gmail.com, not deepseek.com; confirmed_owner=false.
  • free_webmail_dev store Developer email linneamarch498@gmail.com; no developer name; no business website ownership confirmed.
  • uninstall_url_hijack crx uninstall_url_hijack=true; classic monetization shell signal scored +3.0 webstore.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens 3rd-party URL; +2.0 webstore.
  • broad_host_webRequest manifest webRequest + scripting + <all_urls> host permission; ×1.2 multiplier applied on permissions.
  • verified_publisher_cap_0c store months_since_update=17>18mo threshold not quite met, but monetization signals cap discount per v3.5(E).
  • no_csp manifest csp_present=false on MV3; +2.0 network per v2(b) rule applied.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 7000 installs with HIGH permissions.

Permissions Breakdown

  • storage low Stores local settings; minimal risk.
  • webRequest high Can observe all HTTP requests across all URLs; significant surveillance capability.
  • scripting high Injects scripts into any page via <all_urls>; full page content access.
  • alarms low Schedules background tasks; low risk alone.
  • activeTab medium Access to current tab content on user gesture.
  • sidePanel low UI surface only; low risk.
  • <all_urls> (host) high Broad host access combined with webRequest and scripting is maximum reach.

Pillar Scores

Permissions8.50
Reputation7.50
Network4.00
Webstore9.00
Maintenance6.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:32
Listing SHA 59042ed1f4d6…
Force block — not fired
Score recovered no
Elapsed