Ad & Intro Skip for YT, Netflix
hmbnhhcgiecenbbkgdoaoafjpeaboine
Risk Score
6.77
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Privacy policy admits data collection + third-party sharing with no extension-specific scope — worst-case D rule applies (+10 privacy).
- Contacts googleads.g.doubleclick.net (monetization) and fbadcollector.adspyder.io — ad-tech tracking inside an adblocker.
- Uninstall URL hijack via bit.ly short-link: cloaked exfil/redirect destination on removal (+3 webstore).
- Brand impersonation: claims Netflix affiliation without verified ownership, free-webmail dev (+2 reputation).
- declarativeNetRequestWithHostAccess + <all_urls>: can silently redirect or block any request on any site.
Evidence
- monetization_host crx js_external_hosts includes googleads.g.doubleclick.net and fbadcollector.adspyder.io — ad-tech inside an adblock extension.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL targets https://bit.ly/ytadblockui — cloaked 3rd-party destination.
- install_url_hijack crx onInstalled opens 3rd-party URL (target null but flag true).
- privacy_policy_classification api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule +10.
- brand_impersonation store Netflix mentioned in title; developer domain is gmail.com, confirmed_owner=false, is_impersonation=true.
- free_webmail_dev store Developer email autoskipyt@gmail.com with no verified business website; no publisher badge.
- affiliate_hit crx bit.ly listed in js_external_hosts as affiliate/cloaking redirector.
- declarativeNetRequestWithHostAccess_all_urls manifest HIGH permission paired with <all_urls> — can intercept/modify every network request.
Permissions Breakdown
- storage low Standard key-value storage, minimal risk.
- unlimitedStorage low Extends storage quota; low direct risk.
- declarativeNetRequest medium Can block/redirect network requests; matches adblock function.
- declarativeNetRequestWithHostAccess high HIGH perm: modifies requests on all hosts paired with <all_urls>.
- declarativeNetRequestFeedback medium Reads which rules fired; can reveal browsing patterns.
- <all_urls> (host_permissions) high Broad host access across every site; content scripts injected everywhere.
Pillar Scores
Permissions7.50
Reputation7.50
Network6.00
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:10
Listing SHA
8c510615b664…
Force block
— not fired
Score recovered
no
Elapsed
—