https://wazir-x402.duckdns.org/yad/ · Functionality & UI
3 items
Say what you need and Yad does it, on any site in your own browser. Your passwords stay with you, you pick the AI. Yad is your own hand in the browser. It works inside your real Chrome, on your own computer, clicking, typing, and waiting through the repetitive browser work you'd rather hand off: research, form filling, comparisons, the tasks with no API and no button for them. Describe the task in plain language. Yad reads the page, finds what it needs, and gets it done. HOW YAD WORKS: TWO PARTS, AND YOU NEED BOTH Part A is this Chrome extension. It's the hand: it reads the page in front of you and clicks, types, and navigates on it, right in your own logged-in browser. Part B is the Companion, a small free app you download and run once on your own computer. It's the brain: it's the only piece of Yad that ever does the actual AI thinking or touches your API key. Part A alone can't think. Part B alone can't see your browser. Install both once and you're set. The Companion is Windows only for now. Bring your own AI key, Groq, Google Gemini, OpenRouter, or a custom endpoint, or run a model fully locally for free. Yad never holds or resells access to an AI on your behalf. SECURITY, IN PLAIN TERMS Your API key is never stored readable. Not even briefly. Paste it in once, and it's sent one time to your local Companion (Part B), which immediately locks it with Windows' own built-in encryption, DPAPI, tied to your Windows account, so only that account on that machine can ever unlock it again. The extension (Part A) throws away the plaintext and keeps only the encrypted lock from then on. We proved this on a machine with zero memory of us: the real packaged installer, a completely clean folder, no prior state. A freshly started Companion, in a different folder, took nothing but the encrypted lock and correctly unlocked the key and activated the AI provider. Feed it a corrupted lock instead and it fails safely: no crash, nothing activated. A daily spend cap you set yourself, 1000 calls a day by default, checked at the single choke point every AI call in the whole system has to pass through. Nothing routes around it. A one-click Stop button blocks every further call instantly. Both the cap and the kill switch survive a Companion restart, and fail closed: if that saved state is ever missing or unreadable, Yad blocks calls by default instead of quietly letting them through. No task can drain your key while you're away. Your key goes to exactly one place: the AI provider you picked yourself. Never to any server we run. Even Yad's recovery brain, the one thing that phones home to help the agent improve, sends nothing but a bare website hostname and a short reason code. Never your key. Never your page content. Never the full URL. OUR OWN SECURITY INTELLIGENCE We don't just review the code, we try to break it. Before release, the new security code went through an 18-agent, AI-driven adversarial review, built and run by the developer himself, not a third-party firm, not a paid pentest, not a certification: an automated process hunting the code from three separate angles for correctness bugs, security holes, and edge-case failures, with a separate pass re-checking every finding against the real code before it counted. It found 12 real, confirmed issues, including a kill switch that didn't survive a restart and a subprocess launch that could have let a planted fake binary intercept a key. All 12 are fixed and re-verified with live end-to-end tests through Chrome's actual wire protocol. Then we went further and attacked the running app ourselves: eleven ways to sneak a payment page past the checkout guard, five dangerous link types, a DNS-rebinding attempt on the Companion's local control channel, corrupted and oversized messages on the wire between the two parts, the daily cap tested right at its exact edge, and a hundred simultaneous kill-switch toggles hunting for a race condition. All caught, all clean. We then re-ran Yad's full task benchmark: zero crashes, zero regressions. What was already true stays true: passwords and card numbers are masked before anything reaches any AI, cloud or local. Payment and checkout pages are always off limits to autonomous action, even in full-auto mode. No certifications here we haven't earned, no outside audit, no penetration test, nothing "unhackable." Just the mechanism, the tests, and the code, free and open source, all yours to check. Full technical write-up, every proof point included: see the Security page linked from yad's website.
Aug 26, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.