
Official MCP RegistryListed
one.zovo/crx-permission-risk
Score the privilege a Chrome MV3 extension takes from its manifest, and diff permission sets.
First seen 2 Oct 2026. Evidence as of 8 Oct 2026.
3
Tools
From an anonymous probe
1
Source listings
Each with its own history
0
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| analyze_manifest | Static privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty. | Not declared |
| compare_permission_sets | Compares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept. | Not declared |
| explain_permission | Returns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists. | Not declared |
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | one.zovo/crx-permission-risk | 2 Oct 2026 | 8 Oct 2026 | 1 |