Skip to content
MCP server

crx-permission-risk

By zovoAll Zovo servers

Score the privilege a Chrome MV3 extension takes from its manifest, and diff permission sets.

First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.

1
Directories
Collected by InvokeRank
3
Tools
From an anonymous probe
-
ToolBench grade
Not graded by Arcade
-
GitHub stars
No repository data

Tools

ToolDescriptionBehaviour
analyze_manifestStatic privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty.Not declared
compare_permission_setsCompares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept.Not declared
explain_permissionReturns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists.Not declared

Directory listings

DirectoryListingTierFirst seen
Official MCP Registryone.zovo/crx-permission-risk-2 Oct 2026