Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Farm - Slot Machine

ndajcmifndknmkckdcdefkpgcodciggk
Risk Score
4.39
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 19
Rating
Last updated 2025-09-27 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@top.rodeo
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on cdn.cloudapi.stream admits data collection AND third-party sharing without extension-specific scope — worst-case Privacy score.
  • No developer name listed; low install count (19) with multiple developer-controlled external hosts raises accountability concern.
  • Sandbox CSP allows unsafe-inline and unsafe-eval; sandboxed content could evaluate arbitrary scripts.
  • Privacy policy URL is on a CDN subdomain (cloudapi.stream), not the developer's primary domain, reducing trust and traceability.
  • Extension is 11 months stale with only 19 installs; low visibility makes supply-chain takeover harder to detect.

Evidence

  • privacy_policy_admits_third_party_sharing_no_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D clause: +10.0 Privacy.
  • no_developer_name store developer_name is empty string; +1.0 Reputation per rubric.
  • sandbox_csp_unsafe_eval_inline manifest Sandbox CSP includes unsafe-inline and unsafe-eval on script-src; extension_pages CSP is strict.
  • multiple_developer_controlled_external_hosts crx wheel.cloudapi.stream, mines.cloudapi.stream, top.rodeo all contacted; 12 external JS hosts total.
  • no_verified_publisher_no_featured store verified_publisher=false, is_featured_by_google=false; no trust discounts applicable.
  • maintenance_6_to_12_months store months_since_update=11; +3.5 Maintenance score.
  • code_quality_clean crx code_findings_raw empty, obfuscation_score=0.0; Code Quality pillar=0.0.
  • cve_findings_empty crx No CVEs detected in bundled libraries; CVE pillar=0.0.

Permissions Breakdown

  • identity low OAuth identity; low scope, no broad host implied alone.
  • https://www.googleapis.com/* low Standard Google API endpoint; expected with identity permission.
  • https://wheel.cloudapi.stream/* medium Developer-controlled CDN subdomain; opacity risk for data sent here.
  • https://mines.cloudapi.stream/* medium Second developer-controlled CDN subdomain; exfil surface.
  • https://top.rodeo/* low Developer's own domain; expected for a game backend.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.50
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:55
Listing SHA 65b36ce1bd92…
Force block — not fired
Score recovered no
Elapsed