Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Skip Ads - Adblocker for YouTube

lkahpjghmdhpiojknppmlenngmpkkfma
Risk Score
5.64
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 80,000
Rating 4.3
Last updated 2026-05-24 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer adskiper@outlook.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; collects+shares data per classification.
  • YouTube brand impersonation by unverified free-webmail developer (adskiper@outlook.com).
  • jQuery 2.2.4 bundled with 4 medium CVEs (XSS); no CSP present amplifies DOM-sink risk.
  • Description promises ad-blocking but lacks declarativeNetRequest/webRequest — functional mismatch signal.
  • Content scripts on <all_urls> give broad read/write capability across all sites visited.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; 'youtube' referenced, developer not confirmed owner; free-webmail address.
  • generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • cve_jquery_2.2.4 crx 4 medium-severity CVEs in bundled jquery@2.2.4 (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023).
  • no_csp manifest content_security_policy is null; CVE amplifier applies for jquery XSS risk.
  • description_mismatch store Promises ad-blocking but neither declarativeNetRequest nor webRequest declared.
  • host_permission_all_urls manifest host_permissions=[<all_urls>] + content_scripts on <all_urls>; broad site access.
  • free_webmail_dev store developer_email=adskiper@outlook.com; no verified business domain.
  • is_featured_by_google store is_featured_by_google=true; partially mitigates reputation but does not resolve policy/CVE concerns.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.2.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.2.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Stores extension settings locally; low standalone risk.
  • <all_urls> (host_permissions) high Content scripts injected on every site; broad read/modify capability.

Pillar Scores

Permissions5.50
Reputation7.50
Network2.00
Webstore6.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA b1c200160c9d…
Force block — not fired
Score recovered no
Elapsed 40.3s