Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Gold of Egypt - Slot Machine

pllkanemicadpcmkfodglahcocfdgkhj
Risk Score
4.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 14
Rating
Last updated 2025-09-29 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@top.rodeo
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched from CDN (cdn.cloudapi.stream) admits data collection and third-party sharing without scoping to this extension — scores maximum privacy risk.
  • No developer name listed; unverified publisher on an obscure TLD (.rodeo) with only 14 installs.
  • Sandbox CSP allows unsafe-inline and unsafe-eval, enabling script execution outside strict policy.
  • Privacy policy hosted on a CDN subdomain not the developer's own domain; cannot be pinned to accountability.
  • Extension contacts multiple cloudapi.stream subdomains with no transparency about data flows.

Evidence

  • privacy_policy_admits_collection_and_sharing_unscoped api policy fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D)
  • no_developer_name store developer_name is empty string; no verified publisher badge; no recognized org.
  • sandbox_csp_unsafe_eval_inline manifest sandbox CSP includes unsafe-inline and unsafe-eval allowing dynamic code execution in sandboxed pages.
  • privacy_policy_on_cdn_not_dev_domain store Privacy policy URL is cdn.cloudapi.stream, not top.rodeo; weakens accountability.
  • low_install_count store Only 14 installs; tail-attack-surface and small-install anomalies do not trigger (no HIGH perms).
  • host_permissions_cloudapi_stream manifest Two cloudapi.stream subdomains in host_permissions; third-party game backend, unverifiable.
  • no_code_findings_no_obfuscation crx obfuscation_score=0.0, code_findings_raw empty, 17 JS files scanned — code quality clean.
  • maintenance_6_to_12_months store months_since_update=11; falls in 6-12mo band → +3.5 maintenance.

Permissions Breakdown

  • identity low OAuth identity; low risk alone, but paired with googleapis host permission enables auth flows.
  • host: https://www.googleapis.com/* low Google APIs; consistent with identity permission for auth.
  • host: https://wheel.cloudapi.stream/* medium Unknown third-party CDN domain (cloudapi.stream); broad access to a non-transparent host.
  • host: https://mines.cloudapi.stream/* medium Second cloudapi.stream subdomain; game backend but unverifiable third-party host.
  • host: https://top.rodeo/* low Developer's own domain; expected for a game extension.

Pillar Scores

Permissions1.50
Reputation6.50
Network2.00
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:29
Listing SHA 2b2f6df1f91f…
Force block — not fired
Score recovered no
Elapsed