Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Search Seeker

pakokdcamkaoehinfoogagbockgibphc
Risk Score
5.15
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 4
Rating
Last updated 2026-07-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer extensionhub45@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override forces Yahoo-proxied search via searchseeker.co, a classic monetization hijack pattern.
  • Free-webmail dev (extensionhub45@gmail.com) with numbered alias and no verified business identity.
  • Privacy policy is 708 chars, not scoped to this extension, and third-party sharing is silent.
  • declarativeNetRequestWithHostAccess combined with search-provider override gives network interception capability.
  • Only 4 installs with a HIGH-tier permission anomaly flagged; tail-attack-surface risk.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets Search Seeker as default provider, routing queries through searchseeker.co/seek/rd/seek_results.
  • free_webmail_numbered_alias store Developer email extensionhub45@gmail.com is a numbered Gmail alias; no developer name listed.
  • privacy_policy_inadequate api Policy fetched (708 chars), scope_extension=false, data_collection=false, third_party_silence=true; too thin and unscoped.
  • high_perm_low_installs store install_perm_anomaly: 4 installs with HIGH-tier permission (declarativeNetRequestWithHostAccess + search override).
  • verified_publisher store Extension carries verified_publisher=true, partially mitigating reputation risk.
  • no_cve_no_bad_hosts api cve_findings_raw empty, bad_host_hits empty, monetization_hits empty, affiliate_hits empty.
  • declarativeNetRequestWithHostAccess manifest HIGH-impact permission that can redirect/block network requests; paired with search override.
  • no_operator_siblings api operator_cluster sibling_count=0; no known sibling extensions under same fingerprint.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • declarativeNetRequestWithHostAccess high Can intercept/redirect network requests; HIGH-impact capability.
  • chrome_settings_overrides.search_provider (is_default=true) high Silently replaces default search engine; core monetization/hijack vector.
  • host_permissions: *://searchseeker.co/* medium Narrow host scope limited to own domain; reduces blast radius.

Pillar Scores

Permissions7.00
Reputation7.50
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:38
Listing SHA 857ea4db58dd…
Force block — not fired
Score recovered no
Elapsed