Is Fast Search safe?

Medium risk

FastSearch is medium risk. Fast Search sets Chrome's default search provider to services.manualsearch-svc.org. When a search routes through it, install code adds action=ds and a persistent GUID from sync storage, linking requests to your profile over time.

Manuals Libraryv1.25.314Chrome Web Store
45Risk
Who publishes it

Tightrope Interactive - 12 other listings from the same operator, 3 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Manuals Library
Declared legal entity
Tightrope Interactive
Registered address
248 3rd St, Oakland, CA 94607-4375, US
Registered contact
Tightrope Interactive

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Fast Search adds a persistent GUID to search requests

Fast Search sets Chrome's default search provider to services.manualsearch-svc.org.

When a search routes through it, install code adds action=ds and a persistent GUID from sync storage, linking requests to your profile over time.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You search from Chrome after Fast Search is installed.

The manifest makes the extension's manualsearch-svc.org endpoint the browser's default search provider.

The extension did this

The extension routes the search through its service and attaches a persistent GUID.

Dynamic analysis observed the GUID ac636c51-a8d8-60c6-1a4e-a4068bc7c180 stored in Chrome sync storage and reused in the redirect rule.

02EvidenceFIELD TABLE
Fields carried by the redirected search request
FieldValueWhy it matters
Your search terms
weather forecastWhat you typed into the search box. Terms can reveal work topics, internal projects, medical interests, or other personal context.
Your browser-profile GUID
ac636c51-a8d8-60c6-1a4e-a4068bc7c180Lets the search service connect separate searches back to the same browser profile over time.
Search redirect marker
action=dsLabels the request as coming through the extension's search redirect flow.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://services.manualsearch-svc.org/crx/search.php?k=weather%20forecast&action=ds&guid=ac636c51-a8d8-60c6-1a4e-a4068bc7c180
Observed as a redirected search request during dynamic analysis; no request body was recorded.
04EvidenceCODE COMPARE
The code that does this

Manifest override and install-time redirect rule

What it actually does
Default search provider in the deobfuscated manifestmanifest.json
"chrome_settings_overrides": {
    "search_provider": {
        "name": "Web",
        "is_default": true,
        "encoding": "UTF-8",
        "keyword": "search",
        "favicon_url": "https://services.manualsearch-svc.org/favicon.ico",
        "search_url": "https://services.manualsearch-svc.org/search/{searchTerms}",
        "suggest_url": "https://sug.manualsearch-svc.org/sug/?s={searchTerms}"
    }
}
Readable install function stores guid with sync=truelib/ext.js
const install = async () => {
    const src =
        `https://ext.${this.config.apiDomain}/api/v2/json/install?` +
        `&eType=${this.config.eType}&ext.yid=${
            this.config.yID
        }&ext.domain=${await getSetting(
            "domain"
        )}&ext.partner_name=${await getSetting(
            "partner_name"
        )}&ext.region=${await getSetting(
            "region"
        )}&ext.id=${await getSetting(
            "extId"
        )}&ext.version=${await getSetting("extVersion")}`;

    const installRes = await fetch(src, {
        headers: {
            "Content-Type": "application/json",
        },
    });
    if (!installRes.ok) {
        console.error("Error with install req");
        return;
    }
    const config = await installRes.json();
    await Promise.all(
        Object.entries(config).map(
            async ([key, value]) =>
                await setSetting(key, value, key === "guid")
        )
    );
};
Readable install handler creates the redirect rulelib/ext.js
const installHandler = async details => {
    if (details && details.reason && details.reason === "install") {
        await getConfigCookie();
        // first run of extension
        if (!(await getSetting("guid", true))) {
            const extInfo = await chrome.management.getSelf();
            await setSetting("extId", extInfo.id);
            await setSetting("extVersion", extInfo.version);
            const now = new Date();
            const installDate = `${`0${now.getMonth() + 1}`.slice(
                -2
            )}${`0${now.getDate()}`.slice(-2)}${now
                .getFullYear()
                .toString()
                .slice(-2)}`;
            await setSetting("installDate", installDate);
            await install();
            await setTypeTag();
            const guid = await getSetting("guid", true);
            chrome.declarativeNetRequest.updateDynamicRules({
                removeRuleIds: [1],
                addRules: [
                    {
                        id: 1,
                        priority: 1,
                        action: {
                            type: "redirect",
                            redirect: {
                                regexSubstitution: `https://services.${this.config.apiDomain}/crx/search.php?k=\\1&action=ds&guid=${guid}`,
                            },
                        },
                        condition: {
                            regexFilter: `https://services.${this.config.apiDomain}/search/(.*)`,
                            isUrlFilterCaseSensitive: false,
                            resourceTypes: ["main_frame"],
                        },
                    },
                ],
            });
            updateCWSAndLPTab();
            if (await getSetting(TY_COOKIE_NAME)) {
                openUrl(
                    decodeURIComponent(await getSetting(TY_COOKIE_NAME)),
                    false
                );
            }
            startupHandler();
        }
    } else {
        setSetting("firstNT", true, true);
    }
};
Readable service-worker configurationworker.js
const config = {
    apiDomain: "manualsearch-svc.org",
    siteDomain: "s.manualsearch-serp.org",
    yID: "243",
    uninstallID: "358393Ly9hcmNhZGV0YWIuY29t",
    eType: "c",
};
ext.init(config);

chrome.runtime.onInstalled.addListener(ext.installHandler);
chrome.runtime.onStartup.addListener(ext.startupHandler);
05EvidenceTHIRD PARTY LIST
Search infrastructure receiving the requests
  • services.manualsearch-svc.org

    Receives default-search traffic and redirected /crx/search.php requests containing the search term and GUID.

  • sug.manualsearch-svc.org

    Configured as the browser search suggestion endpoint in the extension manifest.

  • ext.manualsearch-svc.org

    Install-time configuration endpoint whose JSON response is stored by the extension, including the GUID when returned.

What it can do

Permissions this extension asks for, as declared in version 1.25.314. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on manualsearch-svc.org

    *://*.manualsearch-svc.org/*

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Store data in your browser

    storage

  • Block and redirect the requests your browser makes

    declarativeNetRequest

Updated 30 September 2026hckckfcmmebhhdmmijemjopbpabgcjbn