Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tetrys - Falling blocks

pkkmmmmckhencoamaonbiidanpnhikbc
Risk Score
3.37
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 80,000
Rating 4.2
Last updated 2026-09-15
Manifest version MV3
CSP present ❌ no
Developer tetrys.org@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without extension-specific scope — worst-case disclosure.
  • Uninstall URL hijack and install URL hijack both flagged; targets null but behavior present in manifest.
  • Developer uses free webmail (gmail) with no developer name listed — low accountability.
  • No CSP defined (MV3 so no MV2 +2.0 penalty, but no content protection).
  • 80K installs with gmail dev email, no developer name, and non-scoped privacy policy is elevated supply-chain risk.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both uninstall and install URL hijack flags set true; targets null but signals monetization/tracking shell pattern.
  • privacy_policy scope_extension=false, data_collection=true, third_party_sharing=true api Policy fetched but not scoped to this extension; admits data collection and 3rd-party sharing — D clause triggers +10.0.
  • developer_email free webmail, no developer_name store tetrys.org@gmail.com with blank developer_name reduces accountability; free-webmail dev pattern.
  • verified_publisher=true + is_featured_by_google=true store Verified and featured badges apply reputation discounts (-3.0 + -2.0 from base 5.0).
  • install_url_hijack + uninstall_url_hijack webstore penalty crx Rubric: +3.0 uninstall URL hijack, +2.0 install URL hijack added to webstore pillar.
  • js_external_hosts: tetrys.org only crx Single external JS host matching dev domain; no bad-host or monetization hits.
  • cve_findings_raw empty, code_findings_raw empty, obfuscation_score 0.0 crx No code-level risk signals detected in 3 scanned JS files.
  • operator_cluster sibling_count=0, no bad/monetization/affiliate hits api No sibling extensions, no threat-intel hits; isolated fingerprint.

Pillar Scores

Permissions0.00
Reputation5.00
Network0.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 15:18
Listing SHA 6411b2bf5844…
Force block — not fired
Score recovered no
Elapsed