Extension Guard
Scan Chrome extension permissions for security risks with risk scoring, dangerous combination detection, and plain-English explanations
Extension Guard
Try a sample
How to find extension permissions
Method 1 — Chrome Web Store: Visit the extension's Chrome Web Store page → scroll down to "Permissions" section → copy the listed permissions.
Method 2 — Installed Extensions: Go to chrome://extensions → click "Details" on any extension → look for "Permissions" section.
Method 3 — manifest.json: If you have the extension source, find manifest.json and copy the "permissions" and "host_permissions" arrays.
Last updated:
This tool is provided as-is for convenience. Output should be verified before use in any production or critical context.
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Browser workflow
Runs instantly in the browser with private local processing and copy/export-ready output.
Browser Workflow
This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.
/extension-guard/
For automation planning, fetch the canonical contract at /api/tool/extension-guard.json.
How to Use Extension Guard
- 1
Paste extension permissions
Copy the permissions from a Chrome extension's Web Store page, manifest.json, or chrome://extensions details. Paste as JSON array, comma-separated, or one per line.
- 2
Click Analyze Permissions
The security engine scores each permission individually and detects dangerous combinations that amplify risk. Results appear instantly.
- 3
Review the risk report
See your overall grade (A-F), risk score (0-100), color-coded permission breakdown, and any dangerous combination alerts with explanations.
- 4
Understand each permission
Every permission includes a plain-English explanation of what it allows and why it matters. Critical and high-risk permissions are flagged prominently.
- 5
Copy or share the report
Click 'Copy Report' to get a markdown-formatted security report you can share with your team or include in documentation.