Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Relay Developer Tools

ncedobpgnmkhcmnnkcimnobpfepidadl
Risk Score
3.54
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 6,000
Rating 5.0
Last updated 2025-02-04 (16 months ago)
Manifest version MV3
CSP present ✅ yes
Developer extensions@fb.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does NOT scope to this extension; data_collection+third_party_sharing admitted without extension-specific disclosure.
  • Content scripts injected on <all_urls> with scripting permission gives broad cross-origin code execution capability on every site.
  • 16 months since last update elevates risk of unpatched issues; falls in 12-24mo stale band.
  • Dynamic script injection (script_src_dynamic) and innerHTML sink (dom_sink_innerhtml_userctrl) detected in bundled JS.
  • Developer listed as Meta but verified_publisher=false; privacy policy links to Google account policy, not Meta/FB policy.

Evidence

  • broad_host_access manifest host_permissions=[<all_urls>] and content_scripts_matches=[<all_urls>]; scripting on every site.
  • generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google account policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_extension store Last updated Feb 4 2025; 16 months since update — 12-24mo stale band (+6.0 maintenance).
  • code_dynamic_script crx script_src_dynamic in injectGlobalHook.js: createElement('script').src=chrome.runtime.getURL(...).
  • code_innerhtml_sink crx dom_sink_innerhtml_userctrl in main.js; CSP present mitigates XSS risk but sink remains.
  • unverified_publisher store Developer claims Meta/extensions@fb.com but verified_publisher=false; no recognition discount applied.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 6000 installs with HIGH-tier permissions.
  • js_external_hosts crx 3 external JS hosts referenced: bugs.chromium.org, fb.me, reactjs.org (likely docs/links, not script loads).

Permissions Breakdown

  • webNavigation medium Allows monitoring all navigation events; paired with <all_urls> increases reach.
  • scripting high Enables programmatic script injection into pages; HIGH capability when combined with <all_urls>.
  • <all_urls> (host_permission) high Broad host access to every site; amplifies scripting and content_script reach.
  • content_scripts <all_urls> high Auto-injected into every page, extends scripting surface to all origins.

Pillar Scores

Permissions5.50
Reputation4.50
Network1.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA e7fad30a9f61…
Force block — not fired
Score recovered no
Elapsed 25.6s