Notebook Web Clipper – Sticky Notes & Save Articles
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 3 days ago
- Version
- v3.4.1
- Artifact
- SHA256 FF0…E51
- Source
- Findings (non-IoC)
Is Notebook Web Clipper – Sticky Notes & Save Articles safe?
This extension declares no special permissions or host permissions in the supplied metadata. Its listed endpoints include allrecipes.com, aktualne.cz, and strings such as action.download and buttonpane.show; the request findings come from dist/ia-summarize.bundle.js, dist/image-card.bundle.js, and dist/image-view.bundle.js, which fit article clipping, summaries, and image cards.
The three high-severity results all use the title OBFUSCATION-invisible_unicode_payload. They point to _locales/fa/messages.json, _locales/te/messages.json, and _locales/kn/messages.json, where invisible Unicode characters can be part of Farsi, Telugu, and Kannada text. If the same pattern were found inside executable code, it would deserve concern. These paths are locale files.
The scanner also flagged network APIs such as NET-FETCH-dist/ia-summarize.bundle.js-527 and NET-XMLHTTPREQUEST-dist/image-card.bundle.js-3758. Those titles identify request code, while the listed endpoints do not identify a login, banking, cookie, or payment target. The blank developer name leaves the publisher unknown, yet the file paths explain the high-severity locale results and the bundled request results without a malware signature or browser-hijacking finding.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceZoho Corp
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The extension is named “Notebook Web Clipper – Sticky Notes & Save Articles” and has the description “Clear the clutter. Clip the web. Save to Notebook.” The strongest signals are the three high-severity findings titled OBFUSCATION-invisible_unicode_payload, located at _locales/fa/messages.json:0, _locales/te/messages.json:0, and _locales/kn/messages.json:0. Those paths are locale message files for Farsi, Telugu, and Kannada. Invisible Unicode markers in language resources are valid writing-system characters in several South Asian and Middle Eastern scripts, so these titles do not establish hidden executable code.
The network findings are concentrated in bundled files. NET-FETCH-dist/ia-summarize.bundle.js-527, NET-XMLHTTPREQUEST-dist/ia-summarize.bundle.js-3758, and the related NET-FETCH findings in dist/ia-summarize.bundle.js identify ordinary request APIs inside a summarization bundle. The same pattern occurs in dist/image-card.bundle.js, including NET-FETCH-dist/image-card.bundle.js-215 and NET-XMLHTTPREQUEST-dist/image-card.bundle.js-3758, and in dist/image-view.bundle.js:215. Fetch and XMLHttpRequest calls fit an extension that clips articles, creates image cards, and summarizes saved content. The available endpoint list includes malformed-looking strings such as action.download, buttonpane.show, and classes.today, alongside recognizable sites such as allrecipes.com and aktualne.cz. Those strings lack the form of a clear command-and-control or credential-targeting domain, and the supplied network findings do not identify data sent to a login, banking, or payment service.
The scanner also reports no malware-signature match, no tool-poisoning match, and no secret finding. The absence of a developer name is a real trust gap, yet _locales/fa/messages.json:0, _locales/te/messages.json:0, and _locales/kn/messages.json:0 provide a direct explanation for every high-severity result. The dist/ paths provide a direct explanation for the repeated network detections. The extension declares no permissions or host permissions in the supplied metadata, which limits the browser access shown here.
A skeptic could point to the blank developer field, the unknown endpoint strings, and the high severity assigned to OBFUSCATION-invisible_unicode_payload. Those points justify keeping the publisher identity unresolved. They do not outweigh the file context: the obfuscation titles occur only in script-specific locale files, while the request titles occur in feature bundles named ia-summarize, image-card, and image-view. No finding title names cookie access, history manipulation, search replacement, credential collection, proxy routing, or malware delivery. A clean runtime trace or publisher verification would add assurance, but the supplied static evidence supports scanner noise rather than intentional harm.
Key Reasons
OBFUSCATION-invisible_unicode_payloadoccurs only in locale files for Farsi, Telugu, and Kannada.- Network findings are located in feature bundles named
ia-summarize,image-card, andimage-view. - No malware-signature, credential-theft, browser-hijacking, or tool-poisoning finding is present.
- The listed endpoint strings do not identify a clear command-and-control or credential-targeting domain.
False Positive Considerations
- Invisible Unicode detection in
_locales/fa/messages.json,_locales/te/messages.json, and_locales/kn/messages.json. - Bundled network API detections in
dist/ia-summarize.bundle.js,dist/image-card.bundle.js, anddist/image-view.bundle.js. - Malformed-looking endpoint strings such as
action.downloadandbuttonpane.showproduced by IoC extraction. - Code-smell and IoC volume from bundled JavaScript.
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 91%.
Edge version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace