Amazon Prime Freevee Skipper: skip ads, intros & more [QVI]
nfodepdbkedfahdadcglakjdmopkobon
Risk Score
2.16
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Developer uses free Gmail; brand_mention flags Amazon impersonation without confirmed ownership.
- No CSP defined (MV3 so no v2 +2.0 penalty, but increases risk for any future vuln).
- Privacy policy discloses third-party data sharing — users should review scope.
- js_external_hosts includes me3x.online, an unknown/unverified domain alongside reference docs.
- Featured badge provides some trust signal but developer identity is not verified publisher.
Evidence
- brand_impersonation_flag store brand_mention.is_impersonation=true for 'amazon'; developer domain is gmail.com, not amazon.
- free_webmail_developer store Developer email toopext@gmail.com; no verified publisher badge; business site toopextensions.com exists.
- featured_by_google store Extension carries 'Follows recommended practices' badge, reducing reputation risk.
- unknown_external_host crx js_external_hosts includes me3x.online alongside legitimate reference sites; purpose unclear.
- privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- permissions_scoped manifest Host permissions limited to Amazon/PrimeVideo domains; matches stated ad/intro-skip function.
- code_clean crx code_findings_raw empty, obfuscation_score=0.0, no CVEs, no bad/monetization/affiliate hits.
Permissions Breakdown
- scripting medium Allows dynamic script injection into pages; scoped to Amazon/PrimeVideo domains.
- storage low Local preference storage; no cross-site risk.
- *://*.primevideo.com/* medium Host access to PrimeVideo; matches stated function.
- *://*.amazon.com/* medium Broad Amazon host access; justified for ad-skipping on Amazon.
- *://*.amazon.co.uk/* low Regional Amazon domain; same rationale as amazon.com.
- *://*.amazon.de/* low Regional Amazon domain; same rationale as amazon.com.
- *://*.amazon.co.jp/* low Regional Amazon domain; same rationale as amazon.com.
Pillar Scores
Permissions2.00
Reputation6.50
Network1.50
Webstore4.00
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:39
Listing SHA
5f2886f954ba…
Force block
— not fired
Score recovered
no
Elapsed
—