Activity log fix: - Injector now writes directly to storage.local in addition to sending runtime messages to the background worker. This fixes the issue where MV3 service worker sleep caused messages to be silently dropped. Dynamic icon colors: - Black "SS" = active, normal - Blue "SS" = reveal mode on - Red "SS" = Silent Send disabled - Icons generated via OffscreenCanvas in the service worker - Updates on every settings change and keyboard shortcut toggle Also adds keyboard shortcuts section to Options page showing current bindings and how to customize them per browser. https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Silent Send
A browser extension (Chrome + Firefox) that intercepts personal information and substitutes it with user-defined replacements before sending to AI services.
Supported services
| Service | Domains | Status |
|---|---|---|
| Claude | claude.ai, claude.ai/code | Tested |
| ChatGPT | chatgpt.com, chat.openai.com | Untested |
| Grok | grok.x.ai, x.com/i/grok | Untested |
| Gemini | gemini.google.com | Untested |
| OpenWebUI | localhost, 127.0.0.1, or custom domain | Untested |
Note: Only Claude has been tested so far. The other services have API interception patterns defined but may need adjustments. PRs welcome.
How it works
- You fill in your Identity — name, email, username, computer name, phone
- Smart patterns auto-catch variations —
jsmith@macbook-pro,John's,/home/jsmith,555.123.4567 - Secret scanner auto-redacts credentials — API keys, tokens, passwords, SSNs, credit cards (zero config)
- You type normally — you see your real text while composing
- On send, it swaps — the extension intercepts the API request and replaces real values with substitutes
- Badge shows count — the extension icon shows how many substitutions were made
- Reveal mode — translates AI responses back to your real data, right in the chat window
Smart pattern examples
| You type | What gets sent |
|---|---|
jsmith@macbook-pro |
ademo@mycomputer |
anyone@gmail.com |
anon@example.com (catch-all) |
John Smith |
Alex Demo |
Smith, John |
Demo, Alex |
John's code |
Alex's code |
/home/jsmith/project |
/home/ademo/project |
~jsmith |
~ademo |
C:\Users\jsmith |
C:\Users\ademo |
(555) 123-4567 |
(555) 000-0000 |
555.123.4567 |
(555) 000-0000 |
macbook-pro |
mycomputer |
Secret scanner (automatic, no configuration needed)
| You type | What gets sent |
|---|---|
sk-proj-abc123xyz789... |
[REDACTED-OPENAI-KEY] |
sk-ant-api01-xyz... |
[REDACTED-ANTHROPIC-KEY] |
ghp_xxxxxxxxxxxxxxxxxxxx |
[REDACTED-GITHUB-TOKEN] |
AKIAIOSFODNN7EXAMPLE |
[REDACTED-AWS-KEY] |
sk_live_abc123... |
[REDACTED-STRIPE-KEY] |
AIzaSyxxxxxxxxxxxxxxxxx |
[REDACTED-GOOGLE-KEY] |
glpat-xxxxxxxxxxxx |
[REDACTED-GITLAB-TOKEN] |
xoxb-xxx-xxx-xxx |
[REDACTED-SLACK-TOKEN] |
Bearer eyJhbGciOi... |
Bearer [REDACTED] |
password=MyS3cret! |
password=[REDACTED] |
api_key=abcdef123456... |
api_key=[REDACTED] |
postgres://user:pass@host |
postgres://REDACTED:REDACTED@host |
-----BEGIN RSA PRIVATE KEY----- |
[REDACTED-PRIVATE-KEY] |
123-45-6789 |
[REDACTED-SSN] |
4111 1111 1111 1111 |
[REDACTED-CARD] |
How to verify it's working
- Badge count on the extension icon shows substitutions per page
- Activity tab in the popup shows a timestamped log of every substitution
- Test tab in the popup lets you type text and see the before/after diff live
- Reveal mode (eye icon) toggles showing real vs substitute data in responses
- Browser DevTools → Console shows
[Silent Send] Substituted N value(s)messages
Installation
Prerequisites
Step 1: Get the code
Open a terminal (Terminal on Mac, Command Prompt or PowerShell on Windows, any terminal on Linux) and run:
git clone https://github.com/outis1one/silent-send.git
cd silent-send
This downloads the extension code to a silent-send folder on your computer.
Chrome
- Open
chrome://extensions/in Chrome - Enable Developer mode (toggle in the top right corner)
- Click Load unpacked
- Navigate to the
silent-sendfolder you cloned and select it - Navigate to any supported AI site — the extension icon appears in your toolbar
That's it for Chrome. No build step, no account, no store, no fees.
Firefox (signed, persistent)
Firefox requires extensions to be cryptographically signed before it will permanently install them. Mozilla provides free signing — no store listing, no review process, no fees. You just need a free Firefox account.
Step 1: Create a free Firefox account
- Go to https://accounts.firefox.com/ and sign up (or sign in if you have one already)
- This is the same account used for Firefox Sync — you may already have one
Step 2: Generate your signing keys
- Go to https://addons.mozilla.org/developers/addon/api/key/
- Sign in with your Firefox account
- You'll see two values on that page:
- JWT issuer — looks like
user:12345678:901 - JWT secret — a long string of random characters
- JWT issuer — looks like
- You need both of these. Copy them or keep the page open.
Step 3: Install dependencies and save your signing keys
In your terminal, inside the silent-send folder:
Mac / Linux:
npm install
cp .env.example .env
Windows (Command Prompt):
npm install
copy .env.example .env
Now open the .env file in any text editor (Notepad, VS Code, etc.) and replace the placeholder values with the two values from step 2:
WEB_EXT_API_KEY="user:12345678:901"
WEB_EXT_API_SECRET="your-jwt-secret-here"
Save and close the file.
Step 4: Build and sign
All platforms (Mac, Linux, Windows with Git Bash):
npm run sign:firefox
The sign script reads your .env file automatically — no need to source it. First-time signing can take 1-5 minutes while Mozilla validates and approves the extension. Subsequent signs are usually faster. When done, you'll find a signed .xpi file in dist/firefox-signed/.
Windows (Command Prompt — if not using Git Bash):
node -e "require('fs').readFileSync('.env','utf8').split('\n').forEach(l=>{const[k,v]=l.split('=');if(k&&v)process.env[k.trim()]=v.trim().replace(/^\"|\"$/g,'')})" && npm run sign:firefox
Windows (PowerShell):
Get-Content .env | ForEach-Object { if ($_ -match '^(.+?)=(.*)$') { [Environment]::SetEnvironmentVariable($matches[1], $matches[2].Trim('"')) } }
npm run sign:firefox
Step 5: Install
- Drag the
.xpifile into any Firefox window, or - Firefox menu → File → Open File → select the
.xpi - Click Add when prompted
Done. The extension is permanently installed — survives restarts, updates, everything. You only need to re-sign if you update to a newer version of Silent Send.
Firefox (temporary, no signing needed)
If you just want to try it out quickly:
Mac / Linux:
npm install && npm run run:firefox
Windows:
npm install && npm run run:firefox
This opens Firefox with the extension pre-loaded. Resets when Firefox closes — useful for testing.
Custom domains (OpenWebUI, etc.)
If you run OpenWebUI or another AI service on a custom domain (not localhost), go to Options → Custom Domains and add your domain (e.g. https://ai.myserver.com). The extension will activate on those domains too.
For Chrome, you'll need to also grant the extension permission to access the new domain via chrome://extensions/ → Silent Send → Details → Site access.
Architecture
manifest.json — Chrome extension manifest (Manifest V3)
manifest.firefox.json — Firefox variant (adds gecko ID for signing)
build.sh — Copies the right manifest to dist/{chrome,firefox}/
src/
background/
service-worker.js — Badge management, logging coordination
content/
injector.js — Content script (isolated world) — loads config, bridges messaging
content.js — Page script (main world) — hooks fetch(), does substitution
content.css — Visual indicators (highlights, reveals)
popup/
popup.html/css/js — Quick access: identity, mappings, activity, test mode
options/
options.html/css/js — Full mapping management, import/export, settings, custom domains
lib/
substitution-engine.js — Core explicit find/replace logic
smart-patterns.js — Auto-detection of emails, names, usernames, hostnames, phones, paths
secret-scanner.js — Auto-detection of API keys, tokens, passwords, SSNs, credit cards
storage.js — Browser storage wrapper
browser-polyfill.js — Chrome/Firefox API compatibility
Privacy
- All data stays local in browser storage
- No external servers, no telemetry, no analytics
- The extension only activates on supported AI sites (and any custom domains you add)
- Your real identity data never leaves your machine