Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AI Grammar Checker & Paraphraser – LanguageTool

oldceeleldhonbafppcapldpdifcinji
Risk Score
4.85
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 2,000,000
Rating 4.7
Last updated 2026-08-12 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer daniel.naber@languagetool.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • eval() used in 4 JS files with no CSP — remote-code-execution risk if any input is attacker-controlled.
  • innerHTML sinks in 5 JS files with no CSP amplifies DOM-XSS exposure across all visited pages.
  • Privacy policy fetched but scope_extension==false and admits data collection + third-party sharing → scores maximum privacy risk.
  • Content script injected on <all_urls> gives broad reach over all browsing; text sent to multiple languagetool API endpoints.
  • No developer display name in listing reduces accountability despite known email domain.

Evidence

  • eval_user_input_multi_file crx eval() of variable found in background.js, changelog.js, feedbackForm.js, trial.js — no CSP to mitigate.
  • dom_sink_innerhtml_no_csp crx innerHTML sinks in content.js, options.js, popup.js, toolbox.js, validator.js with csp_present==false.
  • privacy_policy_generic_with_3p_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0.
  • content_script_all_urls manifest <all_urls> in content_scripts_matches; extension processes text on every page visited.
  • uninstall_url_hijack store uninstall_url_hijack=true; extension registers an uninstall URL redirect.
  • no_csp_mv3 manifest content_security_policy is null; amplifies eval and innerHTML findings.
  • ai_extension_page_content store AI grammar/paraphrase extension processes page text and sends to languagetool API endpoints.
  • featured_by_google store is_featured_by_google=true; applies featured discount to reputation pillar.

Permissions Breakdown

  • activeTab medium Access to current tab on user action; low standalone risk but enables content injection with scripting.
  • storage low Stores user preferences/settings locally.
  • contextMenus low Adds right-click menu items; low risk.
  • scripting medium Can inject JS/CSS into pages; medium risk, paired with <all_urls> content_script match.
  • alarms low Background scheduling; low risk.
  • <all_urls> (content_scripts_matches) high Content script injected on all URLs — broad reach over every site the user visits.

Pillar Scores

Permissions4.80
Reputation4.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality7.00
CVE Exposure0.00

Scoring History

sssiedn3eaa8446dp727562726963xsx 5.17 Medium review 2026-09-06
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%51%44%65%68%28%39%38%30%30%34%29%22 4.41 Medium review 2026-08-05
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 4.85 Medium review 2026-08-05
v3.6'"()&%<zzz><ScRiPt >QDeh(9078)</ScRiPt> 5.07 Medium review 2026-08-05
sssieddrubricxsx 4.57 Medium review 2026-08-04
v3.6 4.85 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA bd0cd1969d5c…
Force block — not fired
Score recovered no
Elapsed 27.7s