Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CSS Inspector

pjknmkdlmmknhihnkdjijnceokddanem
Risk Score
3.06
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 13
Rating
Last updated 2026-03-02 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer tolumhen@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits third-party sharing but is not scoped to this extension — data handling opaque.
  • Developer uses free webmail (gmail.com) with no verified business identity.
  • No CSP declared on MV3 extension; scripting permission adds risk if code is ever injected dynamically.
  • Extremely low install count (13) with no ratings makes track record unverifiable.
  • Privacy policy fetched but scope_extension=false and third_party_sharing=true triggers max privacy score.

Evidence

  • privacy_policy_third_party_sharing api Policy fetched but scope_extension=false and third_party_sharing=true — triggers +10.0 privacy per v3.5 rule D.
  • developer_email_free_webmail store Developer email tolumhen@gmail.com is free webmail; no verified business domain. Reputation +1.5.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
  • no_code_findings crx code_findings_raw is empty and obfuscation_score=0.0; code quality pillar = 0.0.
  • maintenance_recent store Last updated March 2, 2026; months_since_update=3 — within 3-month band, maintenance pillar = 0.0.
  • no_host_permissions manifest No host_permissions or content_scripts_matches declared; reach is limited to activeTab on user action.
  • no_bad_hosts_or_monetization api threat_intel shows empty bad_host_hits, affiliate_hits, and monetization_hits.
  • install_count_very_low store Only 13 installs; no ratings. Blast radius minimal but track record absent.

Permissions Breakdown

  • activeTab low Grants access to current tab only on user action; scoped and low-risk for a CSS inspector.
  • scripting medium Allows injecting scripts into pages; appropriate for CSS inspection but capable of DOM manipulation.
  • clipboardWrite low Write-only clipboard access; consistent with copying CSS values to clipboard.
  • tabs medium Can read tab URLs and metadata; broader than activeTab alone but no host permissions compound it.

Pillar Scores

Permissions2.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA 8058c9d29dc1…
Force block — not fired
Score recovered no
Elapsed 20.5s