Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Monica: All-In-One AI Assist & Smartest AI Agent

ofpnmcalabcbjgholdjcjblkibolbppb
Risk Score
3.51
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 3,000,000
Rating 4.9
Last updated 2026-08-06
Manifest version MV3
CSP present ❌ no
Developer contact@monica.im
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • <all_urls> host permission + scripting enables full page read/write on every site user visits.
  • AI extension processes page content and sends it to monica.im — high-value exfil surface.
  • No CSP declared (MV3 default helps, but no explicit policy); innerHTML sinks present without CSP hardening.
  • Developer name field empty in listing; reduces accountability signal.
  • 3M+ install base amplifies any future compromise or policy change.

Evidence

  • host_permissions <all_urls> + scripting manifest Extension injects content scripts on every URL; high capability surface for AI data processing.
  • AI category + broad host access store Webstore +2.5 AI/Gen-AI extension processing page content; justified-broad discount applied (-1.5).
  • dom_sink_innerhtml_userctrl (2 files) crx innerHTML sinks in content.js and monicaPopup.js; no CSP present → FIX B triggers +2.0 code quality.
  • csp_present == false, MV3 manifest No explicit CSP; MV3 provides strict default so no +2.0 network penalty, but amplifies innerHTML risk.
  • privacy_policy scoped with retention and third-party sharing api Policy fetched, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true → +1.0.
  • is_featured_by_google == true store Featured badge provides -2.0 reputation discount; not verified publisher so cap rules don't apply.
  • domain_age_ct age_days=1207, cert_count=188 api Domain ~3.3 years old, not new, no domain-age penalty.
  • threat_intel clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves, not throwaway.

Permissions Breakdown

  • storage low Standard local data persistence; low standalone risk.
  • scripting medium Allows dynamic script injection into pages; elevated when paired with <all_urls>.
  • sidePanel low UI surface only; no direct data-access capability.
  • contextMenus low Adds right-click menu items; minimal risk surface.
  • <all_urls> (host_permissions) high Grants content-script access to every site user visits; broad reach for an AI extension.

Pillar Scores

Permissions5.50
Reputation3.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Scoring History

xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 2.59 Low review 2026-08-15
%22fsssiedxa$'sssiedx 2.63 Low review 2026-08-15
&#x27;fsssiedxa'sssiedx 3.27 Low review 2026-08-15
&#x22;fsssiedxa sssiedx 2.68 Low review 2026-08-15
fsssiedxa$"sssiedx 3.05 Low review 2026-08-15
<fsssiedxa'sssiedx 2.59 Low review 2026-08-11
<fsssiedxa&#x22;sssiedx 3.04 Low review 2026-08-10
<fsssiedxi sssiedx 3.02 Low review 2026-08-10
<fsssiedxi&#x27;sssiedx 3.22 Low review 2026-08-10
fsssiedx<sssiedx 3.10 Low review 2026-08-10
v3.6</script><script>3mK7(9711)</script> 3.54 Low review 2026-08-05
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 2.70 Low review 2026-08-05
dfb{{98991*97996}}xca 2.77 Low review 2026-08-05
v3.6'"()&%<zzz><ScRiPt >3mK7(9592)</ScRiPt> 3.27 Low review 2026-08-05
<fsssiedxa"sssiedx 3.27 Low review 2026-07-29
<fsssiedxa$"sssiedx 2.90 Low review 2026-07-29
<fsssiedxa$'sssiedx 2.59 Low review 2026-07-29
<fsssiedxa&#x27;sssiedx 2.77 Low review 2026-07-29
<fsssiedxa xx psssiedx 2.54 Low review 2026-07-29
fsssiedxa<sssiedx 3.40 Low review 2026-07-29
sssieddrubricxsx 3.20 Low review 2026-07-29
v3.6 3.51 Low review 2026-06-16
v3.4-rev 4.12 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA 8897b23a099a…
Force block — not fired
Score recovered no
Elapsed 27.5s