Chrome Web Store

ChatGPT Sidebar

by [email protected] · 83 users
565e9462-607e-55cf-a3e8-cb8e070cd2bc | v5.1.4
65/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
6 months ago
Version
v5.1.4
Artifact
SHA256 D64…02C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

69 detail rows

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 6
content-scripts/pageActions.jscontent-scripts/content.jscontent-scripts/smartAnalyzer.js +3 more
-
LOWLocalStorageShouldNotBeUsed 1
chunks/sidepanel-Bkev1piE.js
-
LOWDebuggerStatementsShouldNotBeUsed 2
chunks/sidepanel-Bkev1piE.jscontent-scripts/content.js
-
LOWpostinstall file download 7
content-scripts/pageActions.jscontent-scripts/content.jscontent-scripts/smartAnalyzer.js +4 more
-
LOWNoUseWeakRandom 7
content-scripts/pageActions.jscontent-scripts/content.jscontent-scripts/smartAnalyzer.js +4 more
-
LOWpostinstall obfuscation 6
background.jscontent-scripts/smartAnalyzer.jschunks/sidepanel-Bkev1piE.js +3 more
-
LOWpostinstall crypto operations 8
content-scripts/smartAnalyzer.jscontent-scripts/pageActions.jscontent-scripts/content.js +5 more
-
LOWpostinstall file manipulation 8
content-scripts/smartAnalyzer.jschunks/sidepanel-Bkev1piE.jsbackground.js +5 more
-
LOWpostinstall system command 8
content-scripts/smartAnalyzer.jschunks/sidepanel-Bkev1piE.jsbackground.js +5 more
-
LOWpostinstall network communication 7
content-scripts/smartAnalyzer.jschunks/sidepanel-Bkev1piE.jsbackground.js +4 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

482 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

12 evidence rows available.

Finding Categories

2
Obfuscation
6
Network
482
IoC Indicators

YARA Rules Matched

10 rules(60 hits)
postinstall persistence mechanism LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed postinstall file download NoUseWeakRandom postinstall obfuscation postinstall crypto operations postinstall file manipulation postinstall system command postinstall network communication

Requested Permissions

18 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
tabs
Medium
sidePanel
Low
scripting
Low
declarativeNetRequest
Low
clipboardWrite
Low
storage
Low
https://chatgpt.com/*
Low
https://gemini.google.com/*
Low
https://chat.deepseek.com/*
Low
https://www.qianwen.com/*
Low
https://www.doubao.com/*
Low
https://yuanbao.tencent.com/*
Low
https://grok.com/*
Low
https://kimi.moonshot.cn/*
Low
https://*.kimi.com/*
Low
https://*.kimi.ai/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This extension named 'ChatGPT Sidebar' from developer '[email protected]' presents a mixed signal profile that requires careful interpretation. The most critical observation is the complete absence of malware signatures (0 malware-signature findings, 0 malware findings), which is the strongest indicator against confirmed malicious behavior.

The 563 IoC findings are overwhelmingly benign. The XIOC-DOMAIN-google.com, XIOC-DOMAIN-clients2.google.com, and XIOC-DOMAIN-youtube.com findings reference legitimate Google and YouTube infrastructure. The XIOC-URL-http://www.w3.org/2000/svg finding is a W3C namespace declaration, not an actual network call. The cv.iptc.org domain belongs to the International Press Telecommunications Council's image verification service. While XIOC-DOMAIN-g.sc and XIOC-DOMAIN-p.tj are shortened URL domains that warrant scrutiny, shortened URLs alone do not constitute malicious behavior without evidence of data exfiltration or command-and-control activity.

The network findings show fetch calls in background.js:2, content-scripts/smartAnalyzer.js:1, and content-scripts/content.js at lines 1 and 2. These are generic network call detections that do not specify destination domains or indicate malicious data transmission. The MANIFEST-SENSITIVE-PERM-TABS finding in manifest.json is expected behavior for a sidebar extension that needs to interact with browser tabs to display ChatGPT functionality.

The 60 code-smell findings are classified as low severity and match known false-positive patterns per CVEQ documentation. These include basic JavaScript patterns that trigger rules like postinstall_*, credential_*, and code-quality checks on any non-trivial JavaScript. The 2 obfuscation findings are insufficient to indicate malicious intent without malware signatures co-located in the same files.

Strongest counterargument: A skeptic would argue that an extension claiming to be 'ChatGPT Sidebar' with only 5 users, published by an anonymous Gmail address ([email protected]) rather than a verified OpenAI or known developer, is likely attempting to impersonate legitimate ChatGPT extensions and collect user data. The version number 5.1.4 suggests multiple iterations, potentially testing different approaches. However, this counterargument relies on circumstantial signals rather than concrete evidence. There is no credential theft pattern, no session cookie extraction code, no data exfiltration to suspicious domains, and no malware signatures. The IoC findings do not show traffic to known malicious infrastructure. While the anonymous publisher is a legitimate concern, the absence of actual malicious behavior evidence means the findings are more likely false positives from bundled code and generic pattern matching rather than confirmed malicious activity.

Key Reasons

  • Zero malware signatures detected despite 632 total findings
  • IoC findings are predominantly benign Google/YouTube/W3C domains
  • Code-smell findings (60) are known false-positive patterns
  • Network findings show generic fetch calls without malicious destinations

False Positive Considerations

  • IoC extractor matching benign infrastructure domains (google.com, youtube.com)
  • Code-smell rules firing on standard JavaScript patterns
  • W3C namespace URL misidentified as network IoC
  • Bundled code generating multiplicative IoC findings

Reviewed 2026-04-29; recommended action: monitor; model confidence 72%.

About This Extension

Seamlessly access ChatGPT, DeepSeek, and Gemini side-by-side in your browser sidebar. 🚀 AI Sider — Your All-in-One AI Sidebar for Chrome 📸 Smart Screenshot & Paste to AI • Full Page Screenshot — Capture the entire visible viewport and send it directly to any AI chatbot. • Region Screenshot — Select a specific area to capture and paste into your AI chat. 📋 Copy & Send Page Context Extract text content from any webpage and send it to your preferred AI for summarization, translation, analysis, or Q&A — all without copy-pasting manually. 📄 DOM File for Deep Analysis Generate a simplified, clean HTML representation of any webpage and upload it as a file to AI chatbots. Perfect for asking AI to analyze page structure, extract data, or debug web issues. 🎬 YouTube Video Summarization Automatically extract YouTube subtitles (with timestamps) and send them to AI for instant video summarization. Never watch a long video just to find the key takeaways. ⚡ Smart Page Actions Context-aware action buttons that adapt to the website you're visiting. Get relevant AI-powered shortcuts based on the page content — configured remotely and always up to date. 🌐 Works on Any Website AI Sider lives in your browser's native side panel. Browse any website while chatting with AI — no popups, no tab-switching, no distractions. 🔒 Privacy & Security • No data collection — your conversations stay between you and the AI providers. • No account required — just install and start using. • Open communication via official AI provider websites only. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 💡 USE CASES • 📝 Summarize articles, PDFs, and web pages • 🌍 Translate content on-the-fly • 💻 Debug code with screenshot context • 🎓 Research and study with AI assistance • 🎬 Get YouTube video summaries in seconds • 📊 Analyze webpage data and structure • ✍️ Draft emails and content while browsing ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 📬 SUPPORT & FEEDBACK Have questions or feature requests? Leave a review or reach out — we're constantly improving AI Sider based on your feedback!

Frequently Asked Questions