Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Gemini Chat Folders

ojnjbfdpopfmmaiidnillacpknhcgfek
Risk Score
2.72
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 10,000
Rating 4.2
Last updated 2026-09-03
Manifest version MV3
CSP present ❌ no
Developer fabrizio.massari@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gemini brand impersonation by unverified gmail developer — confirmed non-owner.
  • Privacy policy hosted on Google Sites, does not scope to this extension (generic/unscoped).
  • Content script on gemini.google.com can read all chat content; no CSP protecting the extension.
  • Free-webmail developer (gmail) with no verified business identity increases supply-chain risk.
  • External JS host cdnjs.cloudflare.com loaded without CSP; third-party CDN integrity not enforced.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'gemini'; developer is gmail user, confirmed_owner=false.
  • free_webmail_developer store Developer email fabrizio.massari@gmail.com; no business domain; domain_age_ct not queried.
  • privacy_policy_unscoped api Policy fetched (55414 chars) but scope_extension=false, data_collection=false => generic policy.
  • no_csp manifest content_security_policy is null; external host cdnjs.cloudflare.com used without SRI enforcement.
  • content_script_ai_site manifest Content script injected on gemini.google.com/*; can access all chat text on Gemini.
  • external_js_host crx js_external_hosts includes cdnjs.cloudflare.com (CDN) and gemini.google.com.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no accountability signals.
  • clean_code_scan crx code_findings_raw=[], obfuscation_score=0.0, cve_findings_raw=[]; no malicious indicators found.

Permissions Breakdown

  • storage low Stores local folder/chat data; low risk on its own.
  • sidePanel low Displays sidebar UI; no data access beyond UI rendering.
  • tabs medium Can read tab URLs/titles; moderate risk, scoped to Gemini use-case.
  • https://generativelanguage.googleapis.com/* medium Host permission to Google AI API; scoped to single domain, matches stated AI function.
  • content_scripts: https://gemini.google.com/* medium Injects scripts into Gemini; can read chat content on that site.

Pillar Scores

Permissions2.10
Reputation7.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn401aa55adp727562726963xsx 4.34 Medium review 2026-09-09
v3.6 2.72 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:33
Listing SHA 13b2165a9482…
Force block — not fired
Score recovered no
Elapsed 22.7s