Serveur MCP

crx-permission-risk

one.zovo/crx-permission-risk
Outils développeur Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Analyzes Chrome MV3 extension permissions, scores privilege risk, explains permissions, and compares manifest permission changes.

analyze_manifest
Analyze a Chrome extension manifest
Static privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty.
Schéma d’entrée
{'type': 'object', 'required': ['manifest'], 'properties': {'manifest': {'description': 'The manifest.json content, as a JSON object or a JSON string.'}}}
compare_permission_sets
Diff two permission sets
Compares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept.
Schéma d’entrée
{'type': 'object', 'required': ['before', 'after'], 'properties': {'after': {'type': 'array', 'items': {'type': 'string'}, 'description': 'API permissions in the new version.'}, 'before': {'type': 'array', 'items': {'type': 'string'}, 'description': 'API permissions in the current published version.'}, 'after_hosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'host_permissions in the new version.'}, 'before_hosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'host_permissions in the current published version.'}}}
explain_permission
Explain one permission
Returns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists.
Schéma d’entrée
{'type': 'object', 'required': ['permission'], 'properties': {'permission': {'type': 'string', 'description': 'A permission name such as cookies, or a host pattern such as <all_urls>.'}}}
Ajouté
compare_permission_sets
17 September 2026 12:54
Ajouté
explain_permission
17 September 2026 12:54
Ajouté
analyze_manifest
17 September 2026 12:54

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…