Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Slack Printer

pmoidapkjjlhcdbdjojaekbdlkdjjoab
Risk Score
6.06
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 1,000
Rating 2.1
Last updated 2022-07-21 (47 months ago)
Manifest version MV3
CSP present ✅ yes
Developer hhhust@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Slack brand impersonation by gmail.com dev with no verified ownership; confirmed_owner=false.
  • Privacy policy is generic Google account policy — admits data collection and 3rd-party sharing without scoping to this extension.
  • Extension abandoned for ~47 months (last updated July 2022); zombie risk.
  • Content script injected into all *.slack.com pages enabling full message DOM access.
  • No developer name; free webmail (gmail.com) dev with no business website.

Evidence

  • brand_impersonation store brand_mention: slack referenced, confirmed_owner=false, is_impersonation=true, dev domain=gmail.com.
  • generic_privacy_policy store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • abandoned_extension store months_since_update=47; last updated July 2022. Maintenance pillar = 10.0.
  • content_script_on_slack manifest content_scripts_matches=['https://*.slack.com/*']: full DOM/message read access on Slack.
  • free_webmail_no_dev_name store developer_email=hhhust@gmail.com, developer_name empty, no business website. Reputation floor applied.
  • third_party_backend manifest host_permission and CSP connect-src include slackext.com — unverified third-party server.
  • low_rating store Rating=2.1; below 3.0 threshold indicating user dissatisfaction.
  • telemetry_host crx monetization_hits: ssl.google-analytics.com (telemetry-tier only; +1.0 webstore).

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; moderate data exposure.
  • storage low Local extension storage only; low risk.
  • host: https://slackext.com/* medium Sends/receives data to a third-party domain not owned by Slack.
  • content_scripts: https://*.slack.com/* medium Injects scripts into all Slack pages; can read messages and DOM.

Pillar Scores

Permissions2.50
Reputation8.00
Network2.50
Webstore3.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA eba1d8faeacf…
Force block — not fired
Score recovered no
Elapsed 20.1s