Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Predicting tags on Stackoverflow questions

pihmbhbohheoegbkjmmiajhnjabalfbb
Risk Score
4.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs
Rating
Last updated 2025-06-05 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer puneeth00748@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is a generic freeprivacypolicy.com template: admits data collection and third-party sharing without scoping to this extension.
  • Developer identity is a free Gmail account (puneeth00748@gmail.com) with no verified business presence.
  • Brand impersonation signal: extension name/description prominently references 'Stackoverflow' without confirmed ownership.
  • AI extension sends page/question content to an external HuggingFace Space endpoint with no CSP or auditable data-handling commitment.
  • Maintenance boundary: 12 months since last update places extension at the 6-12 month stale band.

Evidence

  • privacy_policy_generic_admits_sharing api Policy fetched from freeprivacypolicy.com; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
  • free_webmail_developer store Developer email puneeth00748@gmail.com; no business domain; reputation floor triggered at 7.5.
  • brand_impersonation store brand_mention.is_impersonation=true, brands=['stackoverflow'], confirmed_owner=false, not verified/featured → +2.0 reputation.
  • ai_extension_external_endpoint manifest AI category; sends SO question data to HuggingFace Space. No CSP. +2.5 webstore AI signal.
  • no_csp_mv3 crx content_security_policy=null; MV3 default applies but no explicit CSP raises code-quality and network concerns.
  • maintenance_stale_6_12mo store months_since_update=12; falls in 6-12 month band → +3.5 maintenance pillar.
  • no_bad_hosts_no_affiliates api threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no malicious network signals.
  • zero_installs_zero_rating store install_count unparsed (empty string); rating=0; very low blast radius but also unvetted by community.

Permissions Breakdown

  • host_permissions: https://puneeth00748-automated-tagging-browser-extension.hf.space/* low Scoped to single dev-controlled HuggingFace Space endpoint; matches stated ML-tagging function.

Pillar Scores

Permissions0.30
Reputation7.50
Network2.00
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA 3e53bd755979…
Force block — not fired
Score recovered no
Elapsed 24.9s