Is SmartLens AI - Alternative of Google Lens For PC safe?
SmartLens AI is high risk. Right-clicking an image and choosing Analyze with AI, Extract Text, or Scan QR/Barcode sends a base64 copy to api.navy, a third-party AI service. A marker confirmed two POSTs to api.navy/v1/chat/completions with the image embedded.
Who publishes itApp Update - no other listings under this identity
App Update - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Images You Analyze Are Sent to api.navy Without Disclosure
Right-clicking an image and choosing Analyze with AI, Extract Text, or Scan QR/Barcode sends a base64 copy to api.navy, a third-party AI service.
A marker confirmed two POSTs to api.navy/v1/chat/completions with the image embedded.
- Severity
- High unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You right-click an image on any web page and choose Analyze with AI, Extract Text, or Scan QR/Barcode.
SmartLens AI fetches the image, converts it to base64, and POSTs it to api.navy, a third-party AI service, without a disclosure prompt.
This applies to any image on any site. The image leaves your browser and is transmitted to an external server before any result is shown.
Returns {choices[0].message.content: "<AI analysis text>"}; the image has been processed by the remote service.
- Content-Type
- application/json
- Authorization
- Bearer sk-navy-0E2xaNm0xRlwHTD6ILvTTsNr_RMNesAkinmRaFKPeLg
{ "model": "gpt-4o", "messages": [ { "role": "user", "content": [ { "type": "text", "text": "Analyze this image in detail..." }, { "type": "image_url", "image_url": { "url": "data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD...", "detail": "high" } } ] } ], "max_tokens": 4096}- The image you right-clickeddata:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD...
The full image from the page, encoded as base64, the same pixel data visible in your browser.
- Hardcoded API keyBearer sk-navy-0E2xaNm0xRlwHTD6ILvTTsNr_RMNesAkinmRaFKPeLg
A shared credential embedded in the extension source, sent in the Authorization header with every request.
- AI model selectiongpt-4o
Which model processes your image. Defaults to gpt-4o with gpt-4o-mini as fallback.
The code path that transmits the image, from the extension's source.
Image fetch and base64 conversion — readable
// Fetches the image from the page URL and encodes it as base64.// The full image binary is held in memory and passed to the API call.async function fetchImageAsBase64(imageUrl) { const response = await fetch(imageUrl); // downloads the image const blob = await response.blob(); return new Promise((resolve) => { const reader = new FileReader(); reader.onloadend = () => { // reader.result is "data:image/jpeg;base64,<data>" // Split on comma to isolate the raw base64 string const base64 = reader.result.split(',')[1]; resolve(base64); // returned to analyzeWithOpenAI() }; reader.readAsDataURL(blob); });}POST to api.navy with full image — readable
// POSTs the base64 image to api.navy using the hardcoded key.// No user consent prompt is shown before this request is sent.const response = await fetch('https://api.navy/v1/chat/completions', { method: 'POST', headers: { 'Content-Type': 'application/json', 'Authorization': 'Bearer sk-navy-0E2xaNm0xRlwHTD6ILvTTsNr_RMNesAkinmRaFKPeLg' }, body: JSON.stringify({ model: 'gpt-4o', messages: [{ role: 'user', content: [ { type: 'text', text: '<analysis prompt>' }, { type: 'image_url', image_url: { url: `data:image/jpeg;base64,${base64Image}`, // full image here detail: 'high' } } ] }], max_tokens: 4096 })});- api.navy
Receives the full base64-encoded image on every analysis request. Operates an OpenAI-compatible inference API. Not affiliated with or disclosed by the Chrome Web Store listing.
What it can do
Permissions this extension asks for, as declared in version 3.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on api.navy
https://api.navy/*
Read and change your data on every secure site you visit
https://*/*
Add items to the right-click menu
contextMenus
Act on the current tab, but only after you click the extension
activeTab
Start, monitor and manage your downloads
downloads
Store data in your browser
storage
Write to your clipboard
clipboardWrite
Run its own code inside the pages you visit
scripting