Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeOutlier Assistant
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Content script on datacompute.google.com and hume.google.com scrapes full HTML page content including AI prompts and model responses, and POST-transmits them to app.outlier.ai on worker task submission
  2. 02Background script collects all frame URLs from the active tab and transmits them to app.outlier.ai on every queue status event (EQ detection or task backlog count)
  3. 03Background script reads the _csrf and _jwt cookies from app.outlier.ai via chrome.cookies.get to authenticate outbound API requests; cookie values are transmitted in X-CSRF-Token headers to app.outlier.ai
OTHER EXTENSIONS

Is Outlier Assistant safe?

Clean risk

Outlier Assistant helps contributors complete AI labeling tasks on Google DataCompute by sending task data and queue events to app.outlier.ai.

Remotaskv1.16.1Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026jhinngmkfoaklkhedijanghacenapefg

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact