Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Echoes ChatGPT, Claude & more Tool for Search, Tag, Export & Summarize

ppnfnillfndkellpbphafglnljdefjph
Risk Score
5.58
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 9,000
Rating 4.0
Last updated 2026-08-08 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer echoes.support@r2bits.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies permission on major AI platforms (OpenAI, Claude, Gemini) enables session token theft
  • Privacy policy is generic freeprivacypolicy.com template: admits data collection + 3rd-party sharing, not scoped to this extension → Privacy pillar 10.0
  • Brand impersonation: lists ChatGPT, Claude, Gemini in title without verified ownership of those brands
  • No CSP (MV3 no penalty but null CSP) + 4 innerHTML DOM-XSS sinks across dashboard, chat, popup, and demo JS
  • Content scripts run on all major AI platforms with cookies access — AI conversation exfil surface is high

Evidence

  • cookies + AI platform host_permissions manifest cookies declared + host_permissions covering chatgpt.com, claude.ai, gemini.google.com, deepseek.com, grok.com
  • brand_impersonation store brand_mention.is_impersonation=true; brands: chatgpt, claude, gemini; confirmed_owner=false; verified_publisher mitigates partially
  • generic_privacy_policy api freeprivacypolicy.com hosted policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy
  • dom_xss_sinks crx 4 files with dom_sink_innerhtml_userctrl; no CSP present to mitigate; elevated code quality risk
  • is_featured_by_google + verified_publisher store Both verified_publisher=true and is_featured_by_google=true; reduces reputation risk but capped by impersonation signal
  • js_external_hosts crx 12 external hosts including tinyurl.com, feross.org, www.maisieai.com, reactjs.org — >3 distinct domains
  • no_developer_name store developer_name is empty string; email echoes.support@r2bits.com at resolving domain
  • ai_extension_page_content manifest AI-category extension with content_scripts on all major AI chat platforms processes conversation content

Permissions Breakdown

  • scripting medium Can inject scripts into AI platform pages via host_permissions; scoped to declared hosts.
  • activeTab low Temporary access to current tab; lower risk with scripting.
  • storage low Local data persistence; standard for organizer tools.
  • cookies high Can read session cookies on declared AI platform hosts including OpenAI and Google.
  • notifications low User-visible alerts only.
  • declarativeNetRequest medium Can block/redirect network requests; less invasive than webRequest but still notable.
  • alarms low Background scheduling; low standalone risk.
  • host:https://chat.openai.com/* high Content script + cookies on OpenAI — can read conversations and session tokens.
  • host:https://chatgpt.com/* high Content script + cookies on ChatGPT domain.
  • host:https://claude.ai/* high Content script + cookies on Anthropic Claude.
  • host:https://gemini.google.com/* high Content script + cookies on Google Gemini.
  • host:https://www.google-analytics.com/* medium Analytics endpoint; extension can send data to GA.
  • host:https://vercel-r2bits.vercel.app/* medium Dev-controlled backend on Vercel; potential data relay.
  • host:https://chatgpt-conversation-search.firebaseapp.com/* medium Firebase backend; scoped but third-party cloud.

Pillar Scores

Permissions6.50
Reputation5.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn39f20669dp727562726963xsx 4.11 Medium review 2026-09-09
v3.6 5.58 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA f9517834fe92…
Force block — not fired
Score recovered no
Elapsed 35.5s