AI Sider: ChatGPT + DeepSeek + Gemini
The AI review rates the findings as likely false positive, but the risk score (61/100) still counts them.
Analysis record
- Analysed
- 1 months ago
- Version
- v6.0.4
- Artifact
- SHA256 F2E…968
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
20 permissionsAccess and modify data on every website you visit
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
AI Sider: ChatGPT + DeepSeek + Gemini is a browser extension that provides access to multiple AI assistants through a sidebar interface. The security findings for this extension are overwhelmingly driven by known false positive patterns rather than actual malicious behavior.
The extension contains zero malware signatures, which is the most critical indicator of actual malicious code. All 539 IoC findings are from legitimate domains or extraction artifacts. For example, va.truepic.com and c2pa.hash.data are C2PA (Coalition for Content Provenance and Authenticity) domains used for content authenticity verification. The finding xmlhttprequest.prototype.open is a JavaScript property access chain being misread as a domain, a well-documented false positive pattern. Other IoCs include google.com, tailwindcss.com, and cv.iptc.org — all legitimate infrastructure or service domains.
The six network findings originate from content-scripts/smartAnalyzer.js and content-scripts/content.js, which make fetch calls. This is expected behavior for an AI assistant extension that needs to communicate with AI APIs to function. The single manifest finding flags the tabs permission, which is sensitive but necessary for a browser sidebar extension that interacts with web pages.
Sixty code-smell findings are classified as low severity and match basic JavaScript patterns like fetch, crypto, and process.env. These are documented as noise in security analysis and should not drive verdicts.
The strongest counterargument is the anonymous publisher ([email protected]) and high total finding count of 608. However, finding volume is not evidence of malicious intent — the nature of findings matters. The high count is driven by IoC extractor garbage and code-smell noise, not actual threats. The extension's purpose (AI assistant sidebar) is legitimate, and no high-confidence threat indicators like typosquatting, browser hijacking, or credential theft are present. With zero malware signatures and no suspicious domains in the IoC list, this extension represents a classic false positive case where automated scoring inflates risk based on quantity rather than quality of findings.
Key Reasons
- Zero malware signatures detected
- IoC findings are from legitimate domains (C2PA, Google, TailwindCSS) or known FP patterns (property access chains)
- Network calls from content scripts are expected for AI assistant functionality
- Code-smell findings are documented as noise and should not drive verdicts
- No high-confidence threat indicators present (no typosquatting, hijacking, or credential theft)
False Positive Considerations
- IoC extractor garbage (C2PA domains, property access chains misread as domains)
- Code-smell rules matching basic JavaScript patterns
- Legitimate infrastructure domains (google.com, tailwindcss.com)
- Bundled dependency false positives in content scripts
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.
Chrome version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
XB, block all ads
[email protected]
Zent Translate
[email protected]
Google Translate in Side Panel
[email protected]
YT Subtitle - Video Summarizer & Translator
[email protected]
gTab
[email protected]
ChatGPT Sidebar
[email protected]