Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Awesome SAML Tracer

pilkjgooejhajccieiebbihilnclbpej
Risk Score
3.32
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 3,000
Rating 5.0
Last updated 2026-06-07 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer jake.segers@outlook.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + <all_urls>: intercepts all HTTP traffic across every site, high capability for a small-install dev tool.
  • Developer email is free webmail (outlook.com) with no named developer and no verified business domain.
  • Privacy policy scoped to extension but admits third-party sharing without specifying recipients.
  • No CSP declared (MV3 default applies) combined with innerHTML DOM-XSS sink in popup.js.
  • External JS hosts include ko-fi.com and lucide.dev — third-party resources loaded outside dev's own domain.

Evidence

  • webRequest + <all_urls> manifest HIGH permission pair: can read/block every network request across all URLs.
  • free_webmail_developer store Developer email jake.segers@outlook.com; no developer name listed; no business domain.
  • verified_publisher store Verified publisher badge present; partially mitigates identity concern.
  • dom_sink_innerhtml_userctrl crx popup/popup.js: infoBar.innerHTML = html — DOM-XSS sink; csp_present==false amplifies.
  • third_party_sharing_admitted api Privacy policy: scope_extension=true, data_collection=false, third_party_sharing=true, no retention.
  • external_js_hosts crx Extension references ast-web.pages.dev, ko-fi.com, lucide.dev — 3 distinct external domains.
  • no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries detected.
  • operator_cluster api sibling_count=0; no operator cluster risk.

Permissions Breakdown

  • webRequest high Intercepts all network requests across every site visited; paired with <all_urls> raises capability significantly.
  • storage low Local data persistence; low risk in isolation.
  • tabs medium Access to tab URLs and metadata; combined with webRequest increases surveillance surface.
  • downloads medium Can initiate/manage file downloads; relevant for SAML export feature but adds capability.
  • <all_urls> high Broad host access enabling webRequest to intercept traffic on every site.

Pillar Scores

Permissions5.80
Reputation5.50
Network3.00
Webstore0.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-17 07:26
Listing SHA ed769c807a34…
Force block — not fired
Score recovered no
Elapsed