Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Rail Maze Puzzle

nelbpdjegmhhgpfcjclhdmkcglimkjpp
Risk Score
4.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 7
Rating
Last updated 2025-09-22 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer viktornadiezhdin@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on third-party CDN (cloudapi.stream), not scoped to this extension, admits data collection with no retention disclosure.
  • Uninstall URL hijack and install URL hijack flags set — extension intercepts install/uninstall lifecycle events.
  • eval() of dynamic variable in opus.wasm.js — code execution risk in sandbox context.
  • innerHTML assigned from navigator.userAgent — DOM-XSS sink with no CSP guard on sandbox (unsafe-eval/unsafe-inline present).
  • Free-webmail developer with no developer name, 7 installs — minimal accountability and throwaway profile.

Evidence

  • uninstall_url_hijack manifest Extension sets an uninstall URL hook; target null but hook is present — lifecycle hijack signal.
  • install_url_hijack manifest onInstalled opens popup/index.html — low severity internal target but install hijack flag is set.
  • privacy_policy_mismatch store Policy at cdn.cloudapi.stream: fetched=true, scope_extension=false, data_collection=true, retention=false — generic CDN-hosted policy.
  • eval_user_input crx opus.wasm.js uses eval(funcstr) — dynamic code execution in sandbox with unsafe-eval allowed.
  • dom_sink_innerhtml_userctrl crx supportcheck.js assigns navigator.userAgent into innerHTML — DOM-XSS sink; sandbox has unsafe-inline.
  • sandbox_csp_unsafe manifest Sandbox CSP allows unsafe-eval and unsafe-inline on script-src, amplifying eval and innerHTML risks.
  • free_webmail_no_dev_name store Developer is viktornadiezhdin@gmail.com with no developer_name — free webmail, no business accountability.
  • webstore_uninstall_hijack_pattern store Webstore +3.0 for uninstall URL hijack signal per rubric (Pillar 3).

Pillar Scores

Permissions0.00
Reputation5.50
Network0.00
Webstore5.00
Maintenance3.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:30
Listing SHA 8c04e21dcf70…
Force block — not fired
Score recovered no
Elapsed