Paste an extension manifest.json (Chrome MV2/MV3 or Firefox) or a raw permission list. Every permission and host pattern is graded with a risk level and a plain-language explanation, then rolled up into one trust verdict. All analysis runs locally — nothing leaves this page.
Single permissions can look tame — risk compounds when they are combined.
Match patterns decide which sites the extension can read and rewrite. Breadth here outweighs almost everything else.
Dormant until you explicitly approve them later — no immediate exposure, but they reveal what the author wants next.
Risk scale — LOW: routine and scoped. MEDIUM: touches sensitive data or settings with limited blast radius. HIGH: deep reach into history, traffic, credentials, camera/mic or devices. CRIT: escapes the extension sandbox (debugger, native messaging, VPN tunnel, blanket cookies). The catalog covers Chrome MV2/MV3 plus common Firefox grants; unrecognized names are flagged for manual verification rather than guessed. Parsing and scoring happen entirely on this page.