Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SponsorBlock for YouTube - Skip Sponsorships

mnjggcdmjocbbbhaepdhchncahnbgone
Risk Score
3.27
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 2,000,000
Rating 4.6
Last updated 2026-06-26 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer dev@ajay.app
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing: scores maximum privacy risk.
  • Three innerHTML DOM-XSS sinks across content/popup/options scripts with no CSP; elevated under FIX B.
  • install_url_hijack flagged true; onInstalled opens a third-party URL adding webstore risk.
  • brand_mention.is_impersonation=true for YouTube; developer is not YouTube/Google (mitigated by verified+featured).
  • No CSP on MV3 extension with DOM sinks; any XSS in server-returned segment data could escalate.

Evidence

  • privacy_policy_generic_google store Policy URL is myaccount.google.com — Google's own account policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • dom_sink_innerhtml_no_csp crx 3 files contain innerHTML sinks; csp_present=false triggers FIX B escalation to +2.0 per instance; capped at 4.0 code quality.
  • install_url_hijack crx install_url_hijack=true; target=null so destination unknown. Adds +2.0 webstore.
  • brand_impersonation_mitigated store YouTube mentioned in name; is_impersonation=true but verified_publisher+is_featured → +1.0 reputation (v3.2 rule 9).
  • verified_publisher_featured store verified_publisher=true + is_featured_by_google=true; reputation floor=2.0 applied.
  • host_permissions_scoped manifest host_permissions limited to youtube.com and sponsor.ajay.app; justified-broad discount applied to permissions pillar.
  • no_cve_no_bad_hosts api cve_findings_raw empty; bad_host_hits empty; monetization_hits empty; affiliate_hits empty.
  • recently_updated_active store months_since_update=2; maintenance score=0.0.

Permissions Breakdown

  • storage low Local data persistence for skip segments; expected for this category.
  • scripting medium Allows JS injection into pages; scoped to YouTube only via host_permissions.
  • unlimitedStorage low Extended storage for segment database; low standalone risk.
  • https://*.youtube.com/* medium Host access scoped to YouTube; matches stated function.
  • https://sponsor.ajay.app/* low Dev-controlled API endpoint for segment data; narrow and expected.

Pillar Scores

Permissions2.00
Reputation2.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Scoring History

fsssiedxn241b757dza xx pn241b757dzsssiedx 4.02 Medium review 2026-09-04
sssiedn7112a5c9dp727562726963xsx 3.06 Low review 2026-09-04
<fsssiedxa'sssiedx 3.17 Low review 2026-08-18
<fsssiedxi"sssiedx 3.76 Low review 2026-08-18
<fsssiedxi$"sssiedx 3.14 Low review 2026-08-18
<fsssiedx{&#x27;sssiedx 3.35 Low review 2026-08-17
<fsssiedx{$"sssiedx 3.19 Low review 2026-08-17
<fsssiedx{ xx psssiedx 3.27 Low review 2026-08-17
<fsssiedx{ 2.88 Low review 2026-08-17
fsssiedx<sssiedx 3.49 Low review 2026-08-17
xx pfsssiedxb sssiedx 3.49 Low review 2026-08-17
%22fsssiedxb xx psssiedx 3.06 Low review 2026-08-17
'fsssiedxb"sssiedx 3.28 Low review 2026-08-17
%27fsssiedxb$'sssiedx 2.86 Low review 2026-08-17
3.52 Low review 2026-08-17
<fsssiedxbfdsaxax><!--></ScRiPt>asddsssiedx 3.27 Low review 2026-08-17
fsssiedxb<sssiedx 3.13 Low review 2026-08-17
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.64 Low review 2026-08-05
fsssiedxa 3.16 Low review 2026-08-05
sssieddrubricxsx 3.14 Low review 2026-08-05
v3.6"sTYLe='zzz:Expre/**/SSion(VCgk(9852))'bad=" 3.38 Low review 2026-08-05
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 3.41 Low review 2026-08-05
v3.6&n982044=v914183 3.52 Low review 2026-08-05
v3.6&n961306=v928410 3.16 Low review 2026-07-29
v3.6 3.27 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA a8e0eecc002b…
Force block — not fired
Score recovered no
Elapsed 28.5s