MCP 服务器

crx-permission-risk

one.zovo/crx-permission-risk
开发者工具 安全 公开且可连接 MCP 2026-07-28

此 MCP 可以做什么

Analyzes Chrome MV3 extension permissions, scores privilege risk, explains permissions, and compares manifest permission changes.

analyze_manifest
Analyze a Chrome extension manifest
Static privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty.
输入模式
{'type': 'object', 'required': ['manifest'], 'properties': {'manifest': {'description': 'The manifest.json content, as a JSON object or a JSON string.'}}}
compare_permission_sets
Diff two permission sets
Compares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept.
输入模式
{'type': 'object', 'required': ['before', 'after'], 'properties': {'after': {'type': 'array', 'items': {'type': 'string'}, 'description': 'API permissions in the new version.'}, 'before': {'type': 'array', 'items': {'type': 'string'}, 'description': 'API permissions in the current published version.'}, 'after_hosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'host_permissions in the new version.'}, 'before_hosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'host_permissions in the current published version.'}}}
explain_permission
Explain one permission
Returns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists.
输入模式
{'type': 'object', 'required': ['permission'], 'properties': {'permission': {'type': 'string', 'description': 'A permission name such as cookies, or a host pattern such as <all_urls>.'}}}
已添加
compare_permission_sets
2026年9月17日 12:54
已添加
explain_permission
2026年9月17日 12:54
已添加
analyze_manifest
2026年9月17日 12:54

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…