Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ProWritingAid: Grammar Checker & Paraphrasing Tool

npnbdojkgkbcdfdjlfdmplppdphlhhcf
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 200,000
Rating 4.8
Last updated 2026-06-11
Manifest version MV3
CSP present ✅ yes
Developer hello@prowritingaid.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy, not scoped to this extension — admits data collection and 3rd-party sharing without extension-level disclosure.
  • cookies + broad host access (<all_urls>) enables cross-site session token exfiltration across every site visited.
  • dom_sink_innerhtml_userctrl in salesforce-patch.js combined with no content-script CSP creates XSS risk on user pages.
  • function_constructor (new Function) usage in polyfills.js and sidepanel.js; sandbox CSP permits unsafe-eval/unsafe-inline.
  • No developer name listed in store; no verified-publisher badge reduces accountability.

Evidence

  • broad_host_plus_cookies manifest cookies + http://*/* + https://*/* enables cross-origin cookie access on all sites.
  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's policy, not ProWritingAid's extension policy.
  • privacy_scope_extension_false api classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • sandbox_csp_unsafe_eval crx sandbox CSP allows unsafe-eval and unsafe-inline on script-src for *.prowritingaid.com.
  • function_constructor_findings crx new Function() in polyfills.js and sidepanel.js — dynamic code execution pattern.
  • dom_xss_sink crx innerHTML from variable in salesforce-patch.js; csp_present=true but sandbox relaxes restrictions.
  • no_developer_name store developer_name is empty; reduces accountability signal.
  • featured_by_google store is_featured_by_google=true provides partial trust signal; no verified_publisher badge.

Permissions Breakdown

  • tabs medium Can enumerate open tabs and URLs.
  • cookies high Combined with broad host access allows reading session cookies across all sites.
  • storage low Local extension storage only.
  • clipboardRead medium Can silently read clipboard contents at any time.
  • clipboardWrite medium Can overwrite clipboard contents.
  • scripting high Injects JS into pages; broad host access amplifies this.
  • sidePanel low Opens a side panel UI — low standalone risk.
  • http://*/* high Broad host access to all HTTP sites; amplifies cookies and scripting.
  • https://*/* high Broad host access to all HTTPS sites; amplifies cookies and scripting.

Pillar Scores

Permissions7.00
Reputation4.50
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA 10e2410deef5…
Force block — not fired
Score recovered no
Elapsed 25.5s