Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Custom Cursor for Chrome

phfkifnjcmdcmljnnablahicoabkokbg
Risk Score
3.27
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 800,000
Rating 4.4
Last updated 2025-08-07 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer gareilkoberys@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • scripting + <all_urls>: can inject code into every site the user visits
  • new Function() constructor in 5 files enables dynamic code execution
  • No CSP declared (MV3 default applies but no explicit hardening)
  • Developer email is free Gmail with no verified business domain linkage
  • Privacy policy admits third-party sharing but lacks data retention disclosure

Evidence

  • host_permissions=<all_urls> + scripting manifest Can inject arbitrary scripts into every website; high-capability surface.
  • function_constructor in 5 JS files crx new Function() pattern present in background, content, injector, options, popup scripts.
  • verified_publisher + is_featured_by_google store Both badges present; partially offsets reputation concern from Gmail dev email.
  • developer_email=gareilkoberys@gmail.com, no developer_name store Free webmail, no listed developer name — residual reputation risk remains.
  • privacy_policy third_party_sharing=true, retention=false api Policy scoped to extension and discloses collection, but omits retention period.
  • months_since_update=12 store Borderline 6-12 month staleness band; 800K installs amplify supply-chain risk.
  • cve_findings_raw=[], bad_host_hits=[], monetization_hits=[] api No CVEs, no bad hosts, no monetization signals detected.
  • obfuscation_score=0.0, no external JS hosts crx Code is not obfuscated and loads no remote scripts; lowers exfil concern.

Permissions Breakdown

  • tabs medium Exposes tab URLs and metadata across all open tabs.
  • activeTab low Scoped to user-initiated interaction; limited risk alone.
  • storage low Local preference storage for cursor settings; standard.
  • scripting high Programmatic script injection into pages; paired with <all_urls> elevates risk.
  • <all_urls> (host_permissions) high Full cross-origin access to all sites; broadens scripting and tabs risk.

Pillar Scores

Permissions5.50
Reputation3.50
Network2.00
Webstore1.50
Maintenance3.50
Privacy2.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:57
Listing SHA 76c20c8463f0…
Force block — not fired
Score recovered no
Elapsed