Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screenshot - Webpage Screen Capture

okkffdhbfplmbjblhgapnchjinanmnij
Risk Score
4.46
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 50,000
Rating 4.4
Last updated 2025-11-02 (9 months ago)
Manifest version MV3
CSP present ✅ yes
Developer johnsonalma781@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case disclosure.
  • Developer uses free Gmail address with no developer name; identity unverifiable despite verified publisher badge.
  • new Function() constructor found in 7 JS files including content script sm.js — dynamic code execution risk.
  • Content scripts injected on <all_urls> combined with tabCapture grants full-page and screen capture access on every site.
  • install_url_hijack opens third-party imageEditor URL on install; unexpected redirect to external resource.

Evidence

  • privacy_policy_admits_collection_and_sharing_no_scope api policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 (D rule).
  • developer_identity_weak store developer_name empty; email johnsonalma781@gmail.com (free webmail). Verified publisher badge present but identity thin.
  • function_constructor_multiple_files crx new Function() in 7 files including content/sm.js; dynamic code execution risk in broad host-permission context.
  • install_url_hijack manifest install_url_target=imageEditor/imageEditor.html?nanoId= opens external URL on install — v3 webstore signal.
  • broad_host_permissions manifest <all_urls> host_permissions + content_scripts; justified by Screenshot category but still high-reach.
  • js_external_hosts_documentation crx js_external_hosts: github.com, js.foundation, mozilla.github.io, sizzlejs.com — likely license refs, not runtime CDN.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; partially offsets reputation concern.
  • cve_clean api cve_findings_raw empty; jquery 3.7.0 bundled has no flagged CVEs. CVE pillar = 0.0.

Permissions Breakdown

  • storage low Stores settings/state locally; standard for screenshot tools.
  • tabCapture high Captures full tab video/audio stream; core but powerful capability.
  • tabs medium Reads tab URLs and metadata; needed for screenshot context.
  • downloads medium Saves captured images to disk; expected for screenshot extension.
  • offscreen low Allows off-screen document for rendering; MV3 pattern.
  • <all_urls> (host) high Content scripts injected on every site; broad reach for capture.

Pillar Scores

Permissions4.50
Reputation5.50
Network2.00
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:57
Listing SHA 58e26211cb46…
Force block — not fired
Score recovered no
Elapsed