Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Codecode Review for GitLab

npinjojmpfjohjckpnldackfhlflmhaj
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 171
Rating 4.9
Last updated 2026-04-18 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer supergitlabcodereview@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: mentions 'gitlab' but dev is free-webmail gmail with no verified relationship.
  • Privacy policy is Google's own generic policy — scope_extension=false, data_collection=true, third_party_sharing=true; admits data sharing without scoping to this extension.
  • Content script runs on https://*/*, far broader than stated GitLab-only function.
  • Uninstall URL hijack detected; redirects user on removal to unknown destination.
  • Developer contacts personal unknown domain (jevgenij.eu) and Google Analytics with no disclosed purpose.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands=['gitlab']; dev domain=gmail.com; confirmed_owner=false.
  • free_webmail_dev store Developer email supergitlabcodereview@gmail.com; no business website; throwaway-style username.
  • generic_google_privacy_policy store Privacy URL points to myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true.
  • content_script_overbroad manifest content_scripts_matches=['https://*/*'] but extension claims only GitLab functionality.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target not disclosed; 3.0 Webstore penalty applied.
  • external_host_personal_domain crx js_external_hosts includes jevgenij.eu (personal EU domain) and gitlab.jaumo.com; not explained.
  • monetization_hit crx threat_intel.monetization_hits: www.google-analytics.com (telemetry); telemetry-tier only.
  • no_csp manifest content_security_policy=null on MV3; no additional amplifier but raises injection risk.

Permissions Breakdown

  • storage low Standard local storage for settings/state.
  • alarms low Scheduled tasks; minimal standalone risk.
  • notifications low Desktop notifications; low capability risk.
  • host: https://jevgenij.eu/* medium Scoped to unknown personal domain; unclear data flow.
  • host: https://www.google-analytics.com/* medium Telemetry to GA; behavior tracking of unknown scope.
  • content_scripts: https://*/* high Runs JS on every HTTPS page; broad DOM access beyond stated GitLab scope.

Pillar Scores

Permissions4.50
Reputation8.50
Network4.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA 5d9effc609fb…
Force block — not fired
Score recovered no
Elapsed 22.2s