Browser Extensions
TraceMark
Save the useful part of the web — and keep the source attached.
- Chrome + Firefox
- local-first
- MIT
01The problem
A quote without its source is a liability.
Research collected across dozens of tabs ends up as screenshots, pasted fragments, and bookmarks that no longer say why they mattered. When it’s time to cite, the source is gone.
TraceMark saves the useful part of the web with the source attached: selected text is captured together with the page title, URL, and nearby context, organized into collections with tags and notes, and searchable across everything — text, hosts, tags, notes.
02The honest anchor
Mark on page refuses to guess.
Any saved quotation can be re-anchored on its original page — a runtime annotation, not an edit to the website. TraceMark marks only an unambiguous exact match: if the quote is missing, duplicated without enough context, or the page has changed, it says so instead of highlighting something that merely looks right.
That refusal is the same principle as everywhere else in my work — a wrong answer presented confidently is worse than an honest “can’t verify this.”
03Permissions as architecture
Permissions as architecture
Extensions are trusted code in a hostile place, so TraceMark treats browser permissions as an architectural boundary, not an installation formality:
- No content script on every site. Capture runs through browser gestures — toolbar click, context menu, Alt+Shift+S — which grant access to the active page for that invocation only.
- Local AI is opt-in, twice. On Firefox, enabling Ollama requires an explicit data-consent step and then a second click to grant the loopback origin. Grants are rechecked before every request and fail closed if revoked.
- Cleanup is verified, not assumed. If permission removal fails, TraceMark blocks re-enabling behind an explicit “retry permission removal” state rather than assuming the grant is gone.
04Engineering decisions
Engineering decisions
- Local-first, with user-owned backups
- No account, no telemetry, no backend. Research lives in IndexedDB inside the browser profile; complete JSON backups and readable Markdown exports are downloads the user owns. Imports are validated before merging.
- WXT + Svelte across two browsers
-
One codebase builds both MV3 targets. Chrome uses the side panel, Firefox the sidebar, and
the packaging step produces reviewed release ZIPs whose contents are covered by contract
tests —
pnpm checkrebuilds the exact archives before validating them. - Deterministic store screenshots
- Store screenshots are regenerated by a script and validated for filename, dimensions, and size — the images in the repository are reproducible artifacts, not stale by-hand captures.
- Status reported precisely
- v1.0.0 is a validated GitHub release for both browsers. The README says plainly what that means: the packages are reviewed and checksummed, browser-store publication has not happened, and the Firefox ZIP is unsigned. No implied store presence.
05Search, quickly
Search, quickly
06Stack and links
Stack and links
WXT · Svelte · TypeScript · IndexedDB · WebExtensions APIs (side panel, context menus, commands, optional permissions) · Vitest · Playwright-driven packaged-browser checks · GitHub Actions.
Repository · v1.0.0 release · Permission rationale · Privacy policy