Is Autoskip for Youtube™ Ads safe?

High risk

Autoskip for Youtube is high risk. Every time your browser starts, the extension contacts the developer's server and downloads a list of websites, which determines which sites are watched during your session. The developer can change this list anytime without a new version.…

autoskipytv4.0.5Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Developer server controls which sites the extension monitors at runtime

Every time your browser starts, the extension contacts the developer's server and downloads a list of websites, which determines which sites are watched during your session.

The developer can change this list anytime without a new version.

Severity
High unwanted
Type
Unexpected
CWE
CWE-829
Source
Dynamic sandbox
What actually happens
You did this

Your browser starts.

The service worker's top-level scope executes on every browser launch.

The extension did this

The extension fetches a server-controlled list of websites to monitor during your browsing session.

background.js top-level code POSTs {uid: <stored GUID>} to backend.ytadblock.com/yt/updaterule, receives a 'newRule' domain array, and overwrites chrome.storage.local.tr if the new list is longer.

When this fires

On every browser startup

Fires once on every browser startup; the fetch is at top-level scope of the service worker, so it executes unconditionally each time the SW is initialised.

Captured request
POSThttps://backend.ytadblock.com/yt/updaterule

DA confirmed: POST observed on SW startup. chrome.storage.local populated with remote-controlled 'rules' and 'tr' arrays containing DNR-style rule objects targeting youtube.com.

Headers
Content-Type
application/json
Body
{  "uid": "fbc83255-31af-8007-6093-5b6ab214f5b6"}
Fields sent in the targeting-list request
  • Device identifier (uid)
    fbc83255-31af-8007-6093-5b6ab214f5b6

    The same persistent GUID registered at install. Allows the server to tailor the monitoring list per device.

The code that does this

Startup fetch of server-controlled domain list (lines 487-525)

Readable version

Deobfuscated (lines 487–525)

background/background.js
chrome.storage.local.get(['extensionId', 'tr'], function (items) {    const apiUrl = `${baseUrl}/yt/updaterule`;    const requestData = { uid: items.extensionId };    fetch(apiUrl, {        method: 'POST',        headers: { 'Content-Type': 'application/json' },        body: JSON.stringify(requestData)    })        .then(response => {            if (response.ok) {                return response.json();            }        })        .then(tr => {            if (tr?.newRule?.length > 0) {                const existingTr = items.tr || [];                const newRules = tr?.newRule || [];                // Only update if the new rules are actually different/newer                if (newRules.length > existingTr.length) {                    chrome.storage.local.set({ tr: newRules })                }            }        })        .catch(error => {});})
Where the domain list is fetched from
    • backend.ytadblock.com

    Developer-operated backend. Supplies the runtime domain-targeting list and also receives visited URLs that match the list via /yt/rules.

Persistent GUID generated on install and sent to developer backend

On install, the extension generates a random ID permanently tied to your browser and sends it to backend.ytadblock.com.

The ID persists across restarts and is resent on every update, letting the developer track your device over time.

Severity
Low unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You install the extension.

Installation triggers the chrome.runtime.onInstalled event with reason 'install'.

The extension did this

The extension generates a permanent ID for your browser and sends it to the developer's server.

A GUID is created via guidGenerator(), stored in chrome.storage.local as 'extensionId', then immediately POSTed to https://backend.ytadblock.com/yt/intiate with body {uid: <GUID>}.

Captured request
POSThttps://backend.ytadblock.com/yt/intiate

DA confirmed: POST observed immediately after install. chrome.storage.local.extensionId populated with GUID 'fbc83255-31af-8007-6093-5b6ab214f5b6'.

Headers
Content-Type
application/json
Body
{  "uid": "fbc83255-31af-8007-6093-5b6ab214f5b6"}
Fields sent in the install beacon
  • Device identifier (uid)
    fbc83255-31af-8007-6093-5b6ab214f5b6

    A randomly generated ID that permanently identifies your browser to the developer. It does not change unless you reinstall the extension.

The code that does this

Install beacon, GUID generation and POST

Readable version

Deobfuscated (lines 318–384)

background/background.js
function guidGenerator() {    var S4 = function () {        return (((1 + Math.random()) * 0x10000) | 0).toString(16).substring(1);    };    return (S4() + S4() + "-" + S4() + "-" + S4() + "-" + S4() + "-" + S4() + S4() + S4());}chrome.runtime.onInstalled.addListener(function (details) {    const extensionId = guidGenerator()    if (details.reason == "install") {        chrome.storage.local.set({ extensionId: extensionId }).then(() => {            chrome.storage.local.get("extensionId", function (res) {                const apiUrl = `${baseUrl}/yt/intiate`                const requestData = { uid: res.extensionId };                fetch(apiUrl, {                    method: 'POST',                    headers: { 'Content-Type': 'application/json' },                    body: JSON.stringify(requestData)                });            })        })    } else if (details.reason == "update") {        chrome.storage.local.get(null, (res) => {            if (!res.extensionId) {                chrome.storage.local.set({ extensionId })            }            chrome.storage.local.get("extensionId", function (res) {                const apiUrl = baseUrl + '/yt/intiate';                const requestData = { uid: res.extensionId };                fetch(apiUrl, {                    method: 'POST',                    headers: { 'Content-Type': 'application/json' },                    body: JSON.stringify(requestData)                });            })        })    }});
Where the identifier is sent
    • backend.ytadblock.com

    Developer-operated backend. Receives the persistent device GUID on install and on every extension update.

What it can do

Permissions this extension asks for, as declared in version 4.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 4.0.5, which we have not unpacked yet.

  • Read and change your data on every site you visit

    <all_urls>

  • Store data in your browser

    storage

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • See which of your requests its blocking rules matched

    declarativeNetRequestFeedback

declarativeNetRequestWithHostAccess
Updated 30 September 2026hmbnhhcgiecenbbkgdoaoafjpeaboine