Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Folders for Gemini

moolbfcgjpllmjemlgajopefhbekieag
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 3,000
Rating 4.1
Last updated 2026-05-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer ramongallinadcorti@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gemini brand impersonation: dev is gmail user with no verified ownership of 'Gemini' branding.
  • Privacy policy is Google's generic account policy — does not scope data handling to this extension.
  • Uninstall URL hijack redirects to forms.gle (third-party feedback form) on removal.
  • No CSP on MV3 extension with innerHTML DOM-XSS sink in content script on gemini.google.com.
  • Free-webmail developer (gmail) with no business domain — low accountability, easy to sell/transfer.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['gemini'], confirmed_owner=false, dev domain=gmail.com
  • generic_privacy_policy store Policy is Google account policy (460KB); scope_extension=false, data_collection=true, third_party_sharing=true
  • uninstall_url_hijack crx uninstall_url_target=https://forms.gle/tspEfzjCVxRVFv4MA — redirects to 3rd-party form on uninstall
  • dom_xss_sink crx content.js: svg.innerHTML=pathData — uncontrolled DOM-XSS sink, no CSP present
  • free_webmail_dev store Developer email ramongallinadcorti@gmail.com; no business website; low accountability
  • is_featured_by_google store Extension carries Google Featured badge — partial trust signal despite other risks
  • no_csp crx content_security_policy=null on MV3 extension; no mitigation for innerHTML XSS sink
  • cve_findings crx cve_findings_raw=[]; no CVEs detected in bundled libraries

Permissions Breakdown

  • storage low Stores folder/chat organization data locally. Low risk.
  • https://gemini.google.com/* medium Host permission scoped to Gemini only; matches stated function but enables content-script DOM access.

Pillar Scores

Permissions1.30
Reputation7.50
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 384772c1c851…
Force block — not fired
Score recovered no
Elapsed 22.7s