Netskope Extension Risk

Detail view ยท rubric v3.6
โ† Back to catalog

ZACRM๐Ÿฆ

opfakiefjdnefefeaacamdpnipefflkp
Risk Score
7.63
Risk Level: High
Recommendation: ๐Ÿšซ BLOCK
Category AI
Installs 20
Rating โ€”
Last updated 2026-08-19
Manifest version MV3
CSP present โœ… yes
Developer zapautomaticoclick@gmail.com
Verified publisher โŒ no
Featured by Google โŒ no
Privacy policy link
Web Store open โ†—

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • Free-webmail dev (gmail) + <all_urls> + management + scripting: full page/extension control by unverified individual.
  • WhatsApp brand impersonation by unverified developer with no confirmed ownership.
  • Dynamic script creation + new Function() constructors enable arbitrary code execution at runtime.
  • Uninstall URL hijack active; privacy policy fetched but does not scope data collection to this extension.

Evidence

  • free_webmail_dev_high_perm manifest Developer email zapautomaticoclick@gmail.com with <all_urls>+management+scripting; no verified publisher.
  • brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer domain is gmail.com with no confirmed ownership.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension redirects on uninstall to 3rd-party URL.
  • small_install_high_perm api Only 20 installs but holds management+scripting+<all_urls>; high tail-attack-surface.
  • ai_external_hosts crx Contacts api.openai.com, api.deepseek.com, generativelanguage.googleapis.com, admin.lioncrm.site.
  • code_dynamic_exec crx script_src_dynamic in kanban.bundle.js + function_constructor in popup.bundle.js and wasm_license_sw.js.
  • privacy_policy_inadequate store Policy fetched but scope_extension=false, data_collection=false, third_party_silence=true; generic non-scoped.
  • management_permission manifest management permission allows listing and disabling other installed extensions.

Permissions Breakdown

  • storage low Standard local data persistence; low standalone risk.
  • tabs medium Can read tab URLs and titles; moderate surveillance risk.
  • unlimitedStorage low Allows large local data store; minor risk alone.
  • management high Can list/disable/enable other extensions; significant privilege.
  • scripting high Programmatic script injection into pages; paired with <all_urls> is critical.
  • alarms low Scheduled callbacks only; negligible standalone risk.
  • notifications low Display notifications; low risk.
  • <all_urls> high Full host access to all sites; combined with scripting enables universal page manipulation.

Pillar Scores

Permissions8.50
Reputation7.50
Network4.00
Webstore7.50
Maintenance0.00
Privacy9.00
Code Quality7.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:46
Listing SHA 5d1a895e4940โ€ฆ
Force block โ€” not fired
Score recovered no
Elapsed โ€”