Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Proxy Switcher and Manager

onnfghpihccifgojkpnnncpagjcdbjod
Risk Score
5.00
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 100,000
Rating 3.9
Last updated 2025-10-07 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer yokris.dev@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full rerouting of all browser traffic — highest-impact permission for a network tool
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — triggers +10.0 privacy pillar per v3.5 rule D
  • install_url_hijack and uninstall_url_hijack both true — extension opens external URL on install/uninstall
  • Developer email is free webmail (gmail) with no verified business domain; not a verified publisher
  • js_external_hosts includes raw.githubusercontent.com — live remote content fetched at runtime is a supply-chain risk

Evidence

  • proxy_permission manifest proxy declared — can redirect all browser traffic; core function but extreme capability.
  • install_uninstall_url_hijack crx Both install_url_hijack and uninstall_url_hijack are true; target URLs null (not resolvable).
  • privacy_policy_generic store Policy is Google's own account privacy page: scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email yokris.dev@gmail.com; not a verified publisher; no business domain.
  • js_external_hosts_remote crx raw.githubusercontent.com listed as external host — live remote JS/content fetch risk.
  • dom_xss_sink crx ace.js 1.4.12 innerHTML assignment from variable; no CSP present compounds risk.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
  • is_featured_by_google store Extension carries Featured badge — partial trust signal offsetting reputation score.

Permissions Breakdown

  • storage low Stores proxy configs locally; standard for this category.
  • notifications low Alerts user to proxy state changes; low risk.
  • proxy high Full proxy control — can reroute all browser traffic through attacker-controlled servers.

Pillar Scores

Permissions5.50
Reputation6.50
Network3.50
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA 6183bead8dfa…
Force block — not fired
Score recovered no
Elapsed 21.9s