Is SmartLens AI - Alternative of Google Lens For PC safe?

High risk

SmartLens AI is high risk. Right-clicking an image and choosing Analyze with AI, Extract Text, or Scan QR/Barcode sends a base64 copy to api.navy, a third-party AI service. A marker confirmed two POSTs to api.navy/v1/chat/completions with the image embedded.

App Updatev3.1Chrome Web Store
74Risk
Who publishes it

App Update - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Images You Analyze Are Sent to api.navy Without Disclosure

Right-clicking an image and choosing Analyze with AI, Extract Text, or Scan QR/Barcode sends a base64 copy to api.navy, a third-party AI service.

A marker confirmed two POSTs to api.navy/v1/chat/completions with the image embedded.

Severity
High unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You right-click an image on any web page and choose Analyze with AI, Extract Text, or Scan QR/Barcode.

The extension did this

SmartLens AI fetches the image, converts it to base64, and POSTs it to api.navy, a third-party AI service, without a disclosure prompt.

This applies to any image on any site. The image leaves your browser and is transmitted to an external server before any result is shown.

Captured request
POSThttps://api.navy/v1/chat/completions

Returns {choices[0].message.content: "<AI analysis text>"}; the image has been processed by the remote service.

Headers
Content-Type
application/json
Authorization
Bearer sk-navy-0E2xaNm0xRlwHTD6ILvTTsNr_RMNesAkinmRaFKPeLg
Body
{  "model": "gpt-4o",  "messages": [    {      "role": "user",      "content": [        {          "type": "text",          "text": "Analyze this image in detail..."        },        {          "type": "image_url",          "image_url": {            "url": "data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD...",            "detail": "high"          }        }      ]    }  ],  "max_tokens": 4096}
What is sent in the POST body on every image analysis
  • The image you right-clicked
    data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD...

    The full image from the page, encoded as base64, the same pixel data visible in your browser.

  • Hardcoded API key
    Bearer sk-navy-0E2xaNm0xRlwHTD6ILvTTsNr_RMNesAkinmRaFKPeLg

    A shared credential embedded in the extension source, sent in the Authorization header with every request.

  • AI model selection
    gpt-4o

    Which model processes your image. Defaults to gpt-4o with gpt-4o-mini as fallback.

The code that does this

The code path that transmits the image, from the extension's source.

Readable version

Image fetch and base64 conversion — readable

// Fetches the image from the page URL and encodes it as base64.// The full image binary is held in memory and passed to the API call.async function fetchImageAsBase64(imageUrl) {  const response = await fetch(imageUrl);          // downloads the image  const blob = await response.blob();  return new Promise((resolve) => {    const reader = new FileReader();    reader.onloadend = () => {      // reader.result is "data:image/jpeg;base64,<data>"      // Split on comma to isolate the raw base64 string      const base64 = reader.result.split(',')[1];      resolve(base64);  // returned to analyzeWithOpenAI()    };    reader.readAsDataURL(blob);  });}

POST to api.navy with full image — readable

// POSTs the base64 image to api.navy using the hardcoded key.// No user consent prompt is shown before this request is sent.const response = await fetch('https://api.navy/v1/chat/completions', {  method: 'POST',  headers: {    'Content-Type': 'application/json',    'Authorization': 'Bearer sk-navy-0E2xaNm0xRlwHTD6ILvTTsNr_RMNesAkinmRaFKPeLg'  },  body: JSON.stringify({    model: 'gpt-4o',    messages: [{      role: 'user',      content: [        { type: 'text', text: '<analysis prompt>' },        {          type: 'image_url',          image_url: {            url: `data:image/jpeg;base64,${base64Image}`,  // full image here            detail: 'high'          }        }      ]    }],    max_tokens: 4096  })});
Where your images are sent
    • api.navy

    Receives the full base64-encoded image on every analysis request. Operates an OpenAI-compatible inference API. Not affiliated with or disclosed by the Chrome Web Store listing.

What it can do

Permissions this extension asks for, as declared in version 3.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on api.navy

    https://api.navy/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Add items to the right-click menu

    contextMenus

  • Act on the current tab, but only after you click the extension

    activeTab

  • Start, monitor and manage your downloads

    downloads

  • Store data in your browser

    storage

  • Write to your clipboard

    clipboardWrite

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026miijkofiplfeonkfmdlolnojlobmpman