Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon Q Developer | GitHub issue helper

oefafjbablenakmhacfllkmpaeabnnfi
Risk Score
3.50
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 1,000
Rating 5.0
Last updated 2025-10-24 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer amazon-q-developer-addon@amazon.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is generic AWS policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
  • No CSP on MV3 extension; two innerHTML DOM-XSS sinks in content/helpPanel JS running on all GitHub pages.
  • Content script injects into all GitHub repo pages — reads issue content and DOM data from every GitHub visit.
  • Uninstall URL hijack flag set (uninstall_url_hijack=true) — potential redirect on uninstall.
  • AI extension processing GitHub page content with broad React DOM manipulation patterns.

Evidence

  • verified_publisher_amazon store Verified publisher with amazon.com domain; recognized org — reputation floored at 2.0 per hard floor rule.
  • privacy_policy_generic api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5-D).
  • csp_absent_mv3 manifest content_security_policy is null; no CSP present on MV3 extension.
  • dom_sink_innerhtml_no_csp crx Two dom_sink_innerhtml_userctrl findings in content.js and helpPanel.js; csp_present=false → +2.0 each (FIX B).
  • uninstall_url_hijack crx uninstall_url_hijack=true; target=null. Flagged but target unknown — minor webstore risk.
  • content_script_github manifest Content script scoped to https://github.com/*/* only — narrow and matches stated function.
  • no_bad_hosts_no_cves api bad_host_hits=[], affiliate_hits=[], cve_findings_raw=[] — clean threat intel and CVE scan.
  • ai_extension_page_content store AI extension processing GitHub issue page content via side panel; +2.5 webstore AI signal applied.

Permissions Breakdown

  • sidePanel low Opens a side panel UI; no data access beyond what JS can see in panel.
  • tabs medium Can read tab URLs and titles; combined with content scripts enables tab tracking.
  • content_scripts: https://github.com/*/* medium Injects JS into all GitHub repo/issue pages; reads page DOM including issue content.

Pillar Scores

Permissions1.60
Reputation2.00
Network2.00
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA 6ea1d55d30bc…
Force block — not fired
Score recovered no
Elapsed 25.0s