Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon Prime Freevee Skipper: skip ads, intros & more [QVI]

nfodepdbkedfahdadcglakjdmopkobon
Risk Score
2.16
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 30,000
Rating 4.2
Last updated 2026-06-26 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer toopext@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Developer uses free Gmail; brand_mention flags Amazon impersonation without confirmed ownership.
  • No CSP defined (MV3 so no v2 +2.0 penalty, but increases risk for any future vuln).
  • Privacy policy discloses third-party data sharing — users should review scope.
  • js_external_hosts includes me3x.online, an unknown/unverified domain alongside reference docs.
  • Featured badge provides some trust signal but developer identity is not verified publisher.

Evidence

  • brand_impersonation_flag store brand_mention.is_impersonation=true for 'amazon'; developer domain is gmail.com, not amazon.
  • free_webmail_developer store Developer email toopext@gmail.com; no verified publisher badge; business site toopextensions.com exists.
  • featured_by_google store Extension carries 'Follows recommended practices' badge, reducing reputation risk.
  • unknown_external_host crx js_external_hosts includes me3x.online alongside legitimate reference sites; purpose unclear.
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • permissions_scoped manifest Host permissions limited to Amazon/PrimeVideo domains; matches stated ad/intro-skip function.
  • code_clean crx code_findings_raw empty, obfuscation_score=0.0, no CVEs, no bad/monetization/affiliate hits.

Permissions Breakdown

  • scripting medium Allows dynamic script injection into pages; scoped to Amazon/PrimeVideo domains.
  • storage low Local preference storage; no cross-site risk.
  • *://*.primevideo.com/* medium Host access to PrimeVideo; matches stated function.
  • *://*.amazon.com/* medium Broad Amazon host access; justified for ad-skipping on Amazon.
  • *://*.amazon.co.uk/* low Regional Amazon domain; same rationale as amazon.com.
  • *://*.amazon.de/* low Regional Amazon domain; same rationale as amazon.com.
  • *://*.amazon.co.jp/* low Regional Amazon domain; same rationale as amazon.com.

Pillar Scores

Permissions2.00
Reputation6.50
Network1.50
Webstore4.00
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:39
Listing SHA 5f2886f954ba…
Force block — not fired
Score recovered no
Elapsed