Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bluesky Media Downloader

odebdafkpnmipmdangfpfbhdamhdocdb
Risk Score
3.36
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category MediaDownloader
Installs 8,000
Rating 3.9
Last updated 2026-04-30 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer admin@remslabs.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and third-party sharing.
  • Developer name 'dnibnzbckr' is an opaque alias with no verifiable business identity.
  • Sandbox CSP allows 'unsafe-inline' and 'unsafe-eval'; new Function() constructor found in bundled ffmpeg lib.
  • Privacy policy admits third-party sharing without scoping to extension, triggering D-clause (scope_extension=false, data_collection=true, third_party_sharing=true).
  • unpkg.com listed as JS external host — CDN-served code is a supply-chain risk.

Evidence

  • privacy_policy_generic_google store PP URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity_opaque store Developer name 'dnibnzbckr' is a random-looking alias; email admin@remslabs.com, domain resolves but no verified publisher.
  • function_constructor_in_ffmpeg crx new Function() found in lib/ffmpeg/umd/ffmpeg.js — bundled OSS lib, not obfuscated, low direct risk.
  • sandbox_csp_unsafe_eval manifest Sandbox CSP includes 'unsafe-inline' and 'unsafe-eval'; extension_pages CSP is strict.
  • external_host_unpkg crx unpkg.com in js_external_hosts — public CDN, supply-chain risk if fetched at runtime.
  • featured_by_google store is_featured_by_google=true reduces reputation concern somewhat.
  • no_cve_findings crx cve_findings_raw empty; no known-bad hosts or affiliate/monetization hits.
  • content_scripts_narrow manifest content_scripts scoped only to https://bsky.app/* — matches stated function.

Permissions Breakdown

  • offscreen low Creates offscreen documents; needed for media processing in MV3, limited blast radius.
  • downloads medium Can save files to disk; core to MediaDownloader function, justified.
  • storage low Local extension storage only; low risk.
  • content_scripts: https://bsky.app/* low Scoped narrowly to bsky.app; matches stated download function.

Pillar Scores

Permissions1.30
Reputation5.50
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA 2203519e20ea…
Force block — not fired
Score recovered no
Elapsed 22.4s