Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Claude to PDF - Export Claude Chats to PDF, Markdown, JSON

ndnjjjppaaiclfjlnopmnimhhiikkppk
Risk Score
5.35
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 168
Rating 5.0
Last updated 2026-08-29
Manifest version MV3
CSP present ✅ yes
Developer neocrtxai@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: claims Claude affiliation; developer is unverified gmail user with no dev name.
  • Content scripts on 19 AI/cloud platforms read full conversation content; exfil to developer GCP backend.
  • Privacy policy too short (481 chars), unscoped, does not disclose data collection — functionally inadequate.
  • 8 innerHTML DOM-XSS sinks across content scripts injected into AI platforms; chat content could be script-injected.
  • CSP connect-src is '*' (wildcard) allowing exfiltration to any host despite MV3; install_url_hijack also set.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'claude'; developer domain is gmail.com, confirmed_owner=false.
  • free_webmail_no_dev_name store developer_email=neocrtxai@gmail.com, developer_name=''; free webmail + no business identity.
  • privacy_policy_inadequate api Policy fetched (481 chars); scope_extension=false, data_collection=false, third_party_silence=true.
  • csp_connect_src_wildcard manifest CSP connect-src is '* data: blob: filesystem:' — unrestricted outbound connections allowed.
  • install_url_hijack crx install_url_hijack=true; extension opens external URL on install — potential tracking/redirect.
  • dom_xss_sinks_in_content_scripts crx 8 innerHTML sinks across content scripts on AI platforms; DOM-XSS risk from page-sourced HTML.
  • broad_host_permissions_ai_cloud manifest Host perms cover claude.ai, chatgpt, gemini, Dropbox, Notion, GitHub, Yandex plus dev GCP backend.
  • ai_extension_page_content manifest Content scripts on 19 AI/cloud origins; AI extension processing page content per rubric +2.5.

Permissions Breakdown

  • storage low Stores local extension settings; low risk in isolation.
  • downloads medium Can trigger file downloads to user disk; moderate capability.
  • downloads.open medium Can open downloaded files; slight escalation over downloads alone.
  • identity medium Can access OAuth tokens; risk depends on scopes requested at runtime.
  • declarativeNetRequest medium Can block/redirect network requests declaratively; medium impact.
  • activeTab low Scoped to user-activated tab only; limited reach.
  • host_permissions: AI platforms (claude.ai, chatgpt.com, gemini, etc.) high Content script on major AI chat platforms can read full conversation content.
  • host_permissions: cloud storage APIs (Dropbox, Notion, Yandex, GDrive) high API-level access to user cloud storage; data exfil surface if compromised.
  • host_permissions: github.com medium Broad GitHub access; can read repos and interact with API.
  • host_permissions: GCP run.app backend medium Developer-controlled backend receives extension data; trust depends on dev.

Pillar Scores

Permissions5.50
Reputation7.50
Network5.50
Webstore5.50
Maintenance0.00
Privacy9.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 13:52
Listing SHA 7c98a6827eb0…
Force block — not fired
Score recovered no
Elapsed