Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Highlight

nffionklkilbohdkhcmkbbkofhkbmggl
Risk Score
4.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 308
Rating 4.6
Last updated 2025-11-17 (7 months ago)
Manifest version MV3
CSP present ✅ yes
Developer highlight-support@kickdrumtech.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); unfixed.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (score 10).
  • brand_mention flags Google impersonation but developer domain is kickdrumtech.com, not Google.
  • desktopCapture permission can record screen/audio; high-capability for a Docs annotation tool.
  • No developer name listed; identity accountability gap.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.12.1/1.13.8.
  • privacy_policy_inadequate store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.
  • brand_impersonation store brand_mention.is_impersonation=true (Google mentioned); developer domain kickdrumtech.com, not verified publisher.
  • no_developer_name store developer_name is empty; no Offered By identity; +1.0 reputation.
  • desktop_capture_permission manifest desktopCapture declared; can record full screen/audio for a Google Docs productivity extension.
  • is_featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied (Follows recommended practices).
  • maintenance_3_6mo store months_since_update=7; falls in 6-12mo band: +3.5 maintenance.
  • obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty; no malicious code indicators detected.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • unlimitedStorage low Allows large local storage; low risk in isolation.
  • activeTab low Access to current tab only on user gesture; scoped.
  • tabs medium Can read tab URLs and titles; moderate privacy exposure.
  • offscreen low Used for off-screen document processing; low standalone risk.
  • alarms low Scheduling API; minimal risk.
  • identity low OAuth token access; no broad scopes declared.
  • desktopCapture medium Can capture screen/audio; significant capability for a Docs annotation tool.
  • *://*.highlight-api.gethighlight.com/* medium Scoped host permission to developer's own API domain; acceptable but sends data off-device.

Pillar Scores

Permissions3.60
Reputation5.50
Network2.50
Webstore2.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA b0e989e33600…
Force block — not fired
Score recovered no
Elapsed 26.8s