Is Autoskip for Youtube™ Ads safe?
Autoskip for Youtube is high risk. Every time your browser starts, the extension contacts the developer's server and downloads a list of websites, which determines which sites are watched during your session. The developer can change this list anytime without a new version.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Developer server controls which sites the extension monitors at runtime
Every time your browser starts, the extension contacts the developer's server and downloads a list of websites, which determines which sites are watched during your session.
The developer can change this list anytime without a new version.
- Severity
- High unwanted
- Type
- Unexpected
- CWE
- CWE-829
- Source
- Dynamic sandbox
Your browser starts.
The service worker's top-level scope executes on every browser launch.
The extension fetches a server-controlled list of websites to monitor during your browsing session.
background.js top-level code POSTs {uid: <stored GUID>} to backend.ytadblock.com/yt/updaterule, receives a 'newRule' domain array, and overwrites chrome.storage.local.tr if the new list is longer.
On every browser startup
Fires once on every browser startup; the fetch is at top-level scope of the service worker, so it executes unconditionally each time the SW is initialised.
DA confirmed: POST observed on SW startup. chrome.storage.local populated with remote-controlled 'rules' and 'tr' arrays containing DNR-style rule objects targeting youtube.com.
- Content-Type
- application/json
{ "uid": "fbc83255-31af-8007-6093-5b6ab214f5b6"}- Device identifier (uid)fbc83255-31af-8007-6093-5b6ab214f5b6
The same persistent GUID registered at install. Allows the server to tailor the monitoring list per device.
Startup fetch of server-controlled domain list (lines 487-525)
Deobfuscated (lines 487–525)
background/background.jschrome.storage.local.get(['extensionId', 'tr'], function (items) { const apiUrl = `${baseUrl}/yt/updaterule`; const requestData = { uid: items.extensionId }; fetch(apiUrl, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(requestData) }) .then(response => { if (response.ok) { return response.json(); } }) .then(tr => { if (tr?.newRule?.length > 0) { const existingTr = items.tr || []; const newRules = tr?.newRule || []; // Only update if the new rules are actually different/newer if (newRules.length > existingTr.length) { chrome.storage.local.set({ tr: newRules }) } } }) .catch(error => {});})- backend.ytadblock.com
Developer-operated backend. Supplies the runtime domain-targeting list and also receives visited URLs that match the list via /yt/rules.
Persistent GUID generated on install and sent to developer backend
On install, the extension generates a random ID permanently tied to your browser and sends it to backend.ytadblock.com.
The ID persists across restarts and is resent on every update, letting the developer track your device over time.
- Severity
- Low unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You install the extension.
Installation triggers the chrome.runtime.onInstalled event with reason 'install'.
The extension generates a permanent ID for your browser and sends it to the developer's server.
A GUID is created via guidGenerator(), stored in chrome.storage.local as 'extensionId', then immediately POSTed to https://backend.ytadblock.com/yt/intiate with body {uid: <GUID>}.
DA confirmed: POST observed immediately after install. chrome.storage.local.extensionId populated with GUID 'fbc83255-31af-8007-6093-5b6ab214f5b6'.
- Content-Type
- application/json
{ "uid": "fbc83255-31af-8007-6093-5b6ab214f5b6"}- Device identifier (uid)fbc83255-31af-8007-6093-5b6ab214f5b6
A randomly generated ID that permanently identifies your browser to the developer. It does not change unless you reinstall the extension.
Install beacon, GUID generation and POST
Deobfuscated (lines 318–384)
background/background.jsfunction guidGenerator() { var S4 = function () { return (((1 + Math.random()) * 0x10000) | 0).toString(16).substring(1); }; return (S4() + S4() + "-" + S4() + "-" + S4() + "-" + S4() + "-" + S4() + S4() + S4());}chrome.runtime.onInstalled.addListener(function (details) { const extensionId = guidGenerator() if (details.reason == "install") { chrome.storage.local.set({ extensionId: extensionId }).then(() => { chrome.storage.local.get("extensionId", function (res) { const apiUrl = `${baseUrl}/yt/intiate` const requestData = { uid: res.extensionId }; fetch(apiUrl, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(requestData) }); }) }) } else if (details.reason == "update") { chrome.storage.local.get(null, (res) => { if (!res.extensionId) { chrome.storage.local.set({ extensionId }) } chrome.storage.local.get("extensionId", function (res) { const apiUrl = baseUrl + '/yt/intiate'; const requestData = { uid: res.extensionId }; fetch(apiUrl, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(requestData) }); }) }) }});- backend.ytadblock.com
Developer-operated backend. Receives the persistent device GUID on install and on every extension update.
What it can do
Permissions this extension asks for, as declared in version 4.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 4.0.5, which we have not unpacked yet.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
Store an unlimited amount of data in your browser
unlimitedStorage
Block and redirect the requests your browser makes
declarativeNetRequest
See which of your requests its blocking rules matched
declarativeNetRequestFeedback