Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PR Assistant

nccjanflkknfaflafkckpikdklmknacl
Risk Score
3.30
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 8
Rating
Last updated 2026-07-09 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer Tejasangadi456@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail), no developer name, no verified publisher — unverifiable identity.
  • GitHub brand impersonation flagged; developer not a confirmed GitHub owner.
  • Privacy policy on free hosting (GitHub Pages) with data_collection=true and third_party_sharing=true but no retention disclosure.
  • AI extension contacts aistudio.google.com — page content may be sent to external AI API.
  • Only 8 installs, unrated; no community validation and tail-attack-surface opportunity.

Evidence

  • free_webmail_dev_no_name store Developer email is gmail; developer_name is empty; no verified publisher badge.
  • brand_impersonation_github store brand_mention.is_impersonation=true for 'github'; confirmed_owner=false; dev domain is gmail.com.
  • ai_extension_external_host manifest js_external_hosts includes aistudio.google.com; AI processes GitHub PR page content externally.
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
  • very_low_install_count store Only 8 installs; zero ratings; no community trust signal.
  • no_code_findings crx code_findings_raw empty; obfuscation_score 0.0; 8 JS files scanned.
  • no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.

Permissions Breakdown

  • storage low Stores local config/settings; no exfiltration path alone.
  • activeTab medium Grants transient access to current tab on user action; scoped but can read page content.
  • https://github.com/* medium Host permission scoped to GitHub only; matches stated PR-assistant function.

Pillar Scores

Permissions1.50
Reputation7.50
Network2.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 09:09
Listing SHA 2eae145aa099…
Force block — not fired
Score recovered no
Elapsed