Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Youtube Ad Skip Key

hgijpdhbgbfknajdponodgdehhafcbbp
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 4,000
Rating 3.7
Last updated 2024-11-16 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer puntf2@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension name explicitly uses 'Youtube' brand without ownership confirmation.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Developer uses free Gmail; no business identity, no verifiable accountability.
  • 19 months without update on a YouTube-interacting content script raises staleness risk.
  • Featured badge partially mitigates but cannot override unscoped generic privacy policy and brand impersonation.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; 'Youtube' in title without authorization.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0.
  • free_webmail_developer store Developer email puntf2@gmail.com; no business domain; domain_age_ct not queried (free webmail).
  • featured_badge store is_featured_by_google=true; partially reduces reputation risk but caps apply due to staleness >18mo.
  • maintenance_staleness store months_since_update=19; falls in 12-24mo band → Maintenance +6.0.
  • content_script_youtube manifest content_scripts_matches=[https://*.youtube.com/*]; injects into all YouTube pages.
  • no_csp manifest content_security_policy=null; MV3 strict default applies, no additional Network penalty per v2b.
  • code_quality_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty → Code Quality 0.0.

Permissions Breakdown

  • storage low Stores extension settings locally; minimal risk on its own.
  • content_scripts: https://*.youtube.com/* medium Injects scripts into all YouTube pages; scoped to one domain but runs on every YouTube visit.

Pillar Scores

Permissions1.30
Reputation7.50
Network0.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA 84c1d2910030…
Force block — not fired
Score recovered no
Elapsed 19.9s