crx-permission-risk
Score the privilege a Chrome MV3 extension takes from its manifest, and diff permission sets.
사용해야 할까요
품질 및 안전성
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"crx-permission-risk": {
"url": "https://crx-permission-risk-mcp.lipmichal.workers.dev/mcp"
}
}
}원격 엔드포인트
https://crx-permission-risk-mcp.lipmichal.workers.dev/mcpstreamable-http할 수 있는 일
도구 목록
도구 (3)
🟢analyze_manifest(manifest)
Static privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty.
입력 스키마
{
"type": "object",
"properties": {
"manifest": {
"description": "The manifest.json content, as a JSON object or a JSON string."
}
},
"required": [
"manifest"
]
}🟢explain_permission(permission)
Returns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists.
입력 스키마
{
"type": "object",
"properties": {
"permission": {
"type": "string",
"description": "A permission name such as cookies, or a host pattern such as <all_urls>."
}
},
"required": [
"permission"
]
}🟡compare_permission_sets(before, after, before_hosts, after_hosts)
Compares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept.
입력 스키마
{
"type": "object",
"properties": {
"before": {
"type": "array",
"items": {
"type": "string"
},
"description": "API permissions in the current published version."
},
"after": {
"type": "array",
"items": {
"type": "string"
},
"description": "API permissions in the new version."
},
"before_hosts": {
"type": "array",
"items": {
"type": "string"
},
"description": "host_permissions in the current published version."
},
"after_hosts": {
"type": "array",
"items": {
"type": "string"
},
"description": "host_permissions in the new version."
}
},
"required": [
"before",
"after"
]
}커뮤니티
증거