crx-permission-risk

Score the privilege a Chrome MV3 extension takes from its manifest, and diff permission sets.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
93%
Naming quality
87%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~388Tokens (tool definitions)
~843 BTypical response size
Minimal attention impact (0.30% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "crx-permission-risk": {
      "url": "https://crx-permission-risk-mcp.lipmichal.workers.dev/mcp"
    }
  }
}

Remote endpoints

https://crx-permission-risk-mcp.lipmichal.workers.dev/mcpstreamable-http

What it can do

Tool inventory

Tools (3)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢analyze_manifest(manifest)

Static privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty.

Input Schema

{
  "type": "object",
  "properties": {
    "manifest": {
      "description": "The manifest.json content, as a JSON object or a JSON string."
    }
  },
  "required": [
    "manifest"
  ]
}
🟢explain_permission(permission)

Returns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists.

Input Schema

{
  "type": "object",
  "properties": {
    "permission": {
      "type": "string",
      "description": "A permission name such as cookies, or a host pattern such as <all_urls>."
    }
  },
  "required": [
    "permission"
  ]
}
🟡compare_permission_sets(before, after, before_hosts, after_hosts)

Compares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept.

Input Schema

{
  "type": "object",
  "properties": {
    "before": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "API permissions in the current published version."
    },
    "after": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "API permissions in the new version."
    },
    "before_hosts": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "host_permissions in the current published version."
    },
    "after_hosts": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "host_permissions in the new version."
    }
  },
  "required": [
    "before",
    "after"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded3 tools
verifiedversion not recorded3 tools