Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Fast save and repost for Instagram

olenolhfominlkfmlkolcahemogebpcj
Risk Score
6.02
Risk Level: High
Recommendation: 🚫 BLOCK
Category MediaDownloader
Installs 30,000
Rating 4.8
Last updated 2025-12-11 (6 months ago)
Manifest version MV3
CSP present ✅ yes
Developer elmianoor7@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + <all_urls> + webRequest: can exfiltrate Instagram session tokens and observe all cross-site traffic
  • Privacy policy is Google's generic account policy — does NOT scope to this extension; admits data collection and 3rd-party sharing
  • Brand impersonation: extension targets Instagram but developer is unverified gmail user with no business domain
  • Install-URL hijack opens www.instagram.com on install; content_scripts also inject into spector.ac/cx/team (unrelated to stated function)
  • 5 distinct JS external hosts including downloadigs.com, spector.ac/cx/team — scope mismatch beyond Instagram-only stated purpose

Evidence

  • cookies+<all_urls>+webRequest manifest cookies and webRequest both declared with <all_urls> host permission — multiplier applies; cross-site session exfil possible.
  • brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is gmail user with no verified owner relationship.
  • generic_privacy_policy store Policy URL is myaccount.google.com — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • install_url_hijack crx install_url_hijack=true targeting www.instagram.com; onInstalled opens 3rd-party URL.
  • content_scripts_scope_mismatch manifest content_scripts run on spector.ac, spector.cx, spector.team — unrelated to Instagram downloader function.
  • external_hosts crx 6 external JS hosts: downloadigs.com, spector.ac, spector.cx, spector.team, stuk.github.io, www.instagram.com.
  • free_webmail_developer store developer_email=elmianoor7@gmail.com; no business domain; free webmail reputation floor applies.
  • install_url_hijack_webstore store onInstalled opens 3rd-party URL (instagram.com) — +2.0 webstore signal applied.

Permissions Breakdown

  • storage low Local state persistence; low risk.
  • cookies high Can read/write all cookies on all URLs given <all_urls>; session hijack risk.
  • downloads medium Can save files to disk; core to downloader function but abusable.
  • tabs medium Can enumerate open tabs and URLs; privacy risk.
  • webRequest high Can observe all network requests across all URLs; surveillance capability.
  • system.display low Display info; unusual for a downloader but low direct harm.
  • declarativeNetRequest medium Can block/modify network requests declaratively.
  • <all_urls> high Broad host access amplifies cookies and webRequest to full cross-site capability.

Pillar Scores

Permissions7.50
Reputation7.50
Network3.50
Webstore7.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA e5bc1d5b432d…
Force block — not fired
Score recovered no
Elapsed 24.6s