| proxy | Permission | | This permission allows the extension to control the browser's proxy settings. Rated Critical because it can route all traffic through potentially malicious proxies, enabling man-in-the-middle attacks and traffic monitoring. |
| declarativeNetRequest | Permission | | This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites. |
| webRequest | Permission | | This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens. |
| webRequestAuthProvider | Permission | | This permission allows the extension to handle authentication requests and modify authentication headers. Rated Critical because it can intercept login credentials, session tokens, and modify authentication flows to compromise accounts. |
| webRequestBlocking | Permission | | This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates. |
| <all_urls> | Permission | | This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites. |
| http://*/* | Host | | Broad host access — the extension can read/modify content on every website. |
| https://*/* | Host | | Broad host access — the extension can read/modify content on every website. |
| Dangerous Permission Combination: proxy,webRequestBlocking,webRequest | Risk Factor | | Complete control over network traffic and routing |
| Dangerous Permission Combination: proxy,webRequestBlocking,declarativeNetRequest | Risk Factor | | Complete control over network traffic and routing |
| Dangerous Permission Combination: proxy,webRequestBlocking,cookies | Risk Factor | | Allows extensions to intercept web requests, manage cookies, and access identity or certificate-related functionalities, potentially compromising secure access and authentication processes. |
| Dangerous Permission Combination | Risk Factor | | This extension can intercept, modify, and block web requests in real-time. |
| cookies | Permission | | This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites. |
| Dangerous Permission Combination: declarativeNetRequest,proxy,webRequestBlocking | Risk Factor | | Enables extensions to operate in the background, intercept web requests, and manage privacy settings and browsing data, facilitating concealed actions and potentially undetected modifications. |
| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| unlimitedStorage | Permission | | This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data. |
| declarativeNetRequestFeedback | Permission | | This permission provides network request modification logs. Rated Medium because it can monitor network request changes and debug traffic modifications. |
| https://www2.alibaba.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://message.alibaba.com/* | Host | | Host permission — access limited to this URL pattern. |
| http://spider.lianshengdata.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://spider.lianshengdata.com/* | Host | | Host permission — access limited to this URL pattern. |
| http://192.168.0.107:8080/* | Host | | Host permission — access limited to this URL pattern. |
| https://item.taobao.com/* | Host | | Host permission — access limited to this URL pattern. |
| Early Content Script Execution | Risk Factor | | This extension runs content scripts at document_start. |
| alarms | Permission | | This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data. |
| https://*.alibaba.com/* | Permission | Unknown | No classification available for this permission. |
| host_permissions | Permission | Unknown | No classification available for this permission. |