MCPサーバー

crx-permission-risk

one.zovo/crx-permission-risk
開発者向けツール セキュリティ 公開・接続可能 MCP 2026-07-28

このMCPでできること

Analyzes Chrome MV3 extension permissions, scores privilege risk, explains permissions, and compares manifest permission changes.

analyze_manifest
Analyze a Chrome extension manifest
Static privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty.
入力スキーマ
{'type': 'object', 'required': ['manifest'], 'properties': {'manifest': {'description': 'The manifest.json content, as a JSON object or a JSON string.'}}}
compare_permission_sets
Diff two permission sets
Compares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept.
入力スキーマ
{'type': 'object', 'required': ['before', 'after'], 'properties': {'after': {'type': 'array', 'items': {'type': 'string'}, 'description': 'API permissions in the new version.'}, 'before': {'type': 'array', 'items': {'type': 'string'}, 'description': 'API permissions in the current published version.'}, 'after_hosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'host_permissions in the new version.'}, 'before_hosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'host_permissions in the current published version.'}}}
explain_permission
Explain one permission
Returns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists.
入力スキーマ
{'type': 'object', 'required': ['permission'], 'properties': {'permission': {'type': 'string', 'description': 'A permission name such as cookies, or a host pattern such as <all_urls>.'}}}
追加
compare_permission_sets
2026年9月17日12:54
追加
explain_permission
2026年9月17日12:54
追加
analyze_manifest
2026年9月17日12:54

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…