crx-permission-risk

Score the privilege a Chrome MV3 extension takes from its manifest, and diff permission sets.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
93%
命名质量
87%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~388token 数(工具定义)
~843 B典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.30%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "crx-permission-risk": {
      "url": "https://crx-permission-risk-mcp.lipmichal.workers.dev/mcp"
    }
  }
}

远程端点

https://crx-permission-risk-mcp.lipmichal.workers.dev/mcpstreamable-http

它能做什么

工具清单

工具(3)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢analyze_manifest(manifest)

Static privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty.

输入模式

{
  "type": "object",
  "properties": {
    "manifest": {
      "description": "The manifest.json content, as a JSON object or a JSON string."
    }
  },
  "required": [
    "manifest"
  ]
}
🟢explain_permission(permission)

Returns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists.

输入模式

{
  "type": "object",
  "properties": {
    "permission": {
      "type": "string",
      "description": "A permission name such as cookies, or a host pattern such as <all_urls>."
    }
  },
  "required": [
    "permission"
  ]
}
🟡compare_permission_sets(before, after, before_hosts, after_hosts)

Compares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept.

输入模式

{
  "type": "object",
  "properties": {
    "before": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "API permissions in the current published version."
    },
    "after": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "API permissions in the new version."
    },
    "before_hosts": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "host_permissions in the current published version."
    },
    "after_hosts": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "host_permissions in the new version."
    }
  },
  "required": [
    "before",
    "after"
  ]
}

社区

评价此服务器

证据

最近观测

已验证未记录版本3 个工具
已验证未记录版本3 个工具