Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Stylebot

oiaejidbmkiecgbjeifoejpgmdaleoha
Risk Score
4.03
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 200,000
Rating 4.3
Last updated 2024-05-17
Manifest version MV3
CSP present ❌ no
Developer ahuja.ankit@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • content_scripts on <all_urls> gives read/write DOM access across every site visited.
  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • eval() and new Function() in bundled RequireJS and multiple entry points without CSP protection.
  • Developer uses free Gmail address; no verified business domain for accountability.
  • Last updated ~13 months ago; stale for a widely-installed (200K) CSS-injection tool.

Evidence

  • content_scripts_all_urls manifest content_scripts matches <all_urls> — injects into every page the user visits.
  • generic_privacy_policy store Privacy policy is Google's account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • eval_in_requirejs crx eval_user_input in monaco-editor/iframe/node_modules/requirejs/require.js; no CSP to mitigate.
  • function_constructor_multi_files crx new Function() found in editor, inject-css, options, popup, readability, sync entry points.
  • gmail_developer store Developer email ahuja.ankit@gmail.com; free webmail, no business domain resolved.
  • no_csp manifest content_security_policy is null (MV3 default strict CSP applies, but no explicit extension CSP declared).
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; mitigates reputation concern.
  • stale_13mo store Last updated May 2024 (~13 months); 200K installs with no recent update is a supply-chain risk.

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; needed for CSS injection per-site.
  • storage low Stores user CSS styles locally.
  • identity low OAuth token for Google Drive sync; no broad scopes declared.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • unlimitedStorage low Allows large CSS/style storage; no data-exfil risk alone.
  • content_scripts <all_urls> high Injects scripts into every page; high REACH for a CSS editor.
  • host_permissions: drive.google.com, googleapis.com, fonts.googleapis.com medium Scoped to Google APIs for Drive sync and font loading; narrow but sensitive.

Pillar Scores

Permissions4.00
Reputation3.50
Network2.00
Webstore1.50
Maintenance3.50
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:33
Listing SHA a47c65655322…
Force block — not fired
Score recovered no
Elapsed 29.5s