Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bookmark Manager and Viewer

mnhojcjhcilkgkmijhphlbmghmmdhlfg
Risk Score
4.31
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 10,000
Rating 3.9
Last updated 2026-06-09
Manifest version MV3
CSP present ❌ no
Developer inb.cor@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (scope_extension=false, admits data collection & 3rd-party sharing) — scores maximum privacy risk.
  • Developer uses free Gmail address (inb.cor@gmail.com) with no verified business domain — low accountability.
  • Install URL hijack detected: onInstalled opens internal page — minor but flags monetization/tracking pattern.
  • Uninstall URL hijack flag set — combined with install hijack raises shell-pattern concern despite no external target confirmed.
  • Geo-diverse JS hosts (CA/IN/NL/US, 4 countries) and 12 external JS hosts listed in fingerprint — broad external surface for a bookmark tool.

Evidence

  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension. scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_gmail_no_domain store Developer email inb.cor@gmail.com; brand_mention.developer_domain=gmail.com; no business domain registered.
  • install_url_hijack crx install_url_hijack=true; target=/data/panel/index.html?in=tab (internal, not 3rd-party).
  • uninstall_url_hijack crx uninstall_url_hijack=true; uninstall_url_target=null — target unresolved, rule triggered.
  • host_geo_diversity crx JS hosts span 4 countries (CA, IN, NL, US); 12 distinct external JS hosts in operator fingerprint.
  • dom_sink_innerhtml crx jquery-3.7.1.js contains innerHTML assignment from variable; no CSP present — DOM-XSS risk elevated.
  • featured_by_google store is_featured_by_google=true — partial trust signal, mitigates but does not eliminate reputation concerns.
  • no_cve_findings crx cve_findings_raw empty; jquery 3.7.1 has no known CVEs in OSV scan. CVE pillar=0.

Permissions Breakdown

  • storage low Stores extension settings/bookmark data locally. Expected for this category.
  • activeTab low Accesses current tab on user gesture only. Limited scope.
  • bookmarks medium Full read/write access to all user bookmarks — core function but sensitive data.
  • favicon low Fetches site favicons for display. Low-risk.
  • notifications low Desktop notifications without host access. Low standalone risk.
  • contextMenus low Adds right-click menu items. Low risk.
  • declarativeContent low Matches page conditions to show extension UI. No content read.

Pillar Scores

Permissions2.30
Reputation6.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA 23cab8f2423e…
Force block — not fired
Score recovered no
Elapsed 25.7s