| scripting | Permission | | This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to. |
| webRequest | Permission | | This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens. |
| cookies | Permission | | This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites. |
| Dangerous Permission Combination: scripting,cookies,webRequest | Risk Factor | | Enables extensions to interact with scripts, modify files and downloads, and alter browsing history and bookmarks, potentially affecting data integrity and user control. |
| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation |
| tabs | Permission | | This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns. |
| activeTab | Permission | | This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions. |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| http://*.ounass.ae/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.ounass.ae/* | Host | | Host permission — access limited to this URL pattern. |
| http://ounass.ae/* | Host | | Host permission — access limited to this URL pattern. |
| https://ounass.ae/* | Host | | Host permission — access limited to this URL pattern. |
| http://*.ounass.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.ounass.com/* | Host | | Host permission — access limited to this URL pattern. |
| http://ounass.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://ounass.com/* | Host | | Host permission — access limited to this URL pattern. |
| http://*.ounass.qa/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.ounass.qa/* | Host | | Host permission — access limited to this URL pattern. |
| http://ounass.qa/* | Host | | Host permission — access limited to this URL pattern. |
| https://ounass.qa/* | Host | | Host permission — access limited to this URL pattern. |
| http://localhost:4180/* | Host | | Host permission — access limited to this URL pattern. |
| http://localhost:3001/* | Host | | Host permission — access limited to this URL pattern. |
| http://jarvis.atg.digital/* | Host | | Host permission — access limited to this URL pattern. |
| https://jarvis.atg.digital/* | Host | | Host permission — access limited to this URL pattern. |
| https://beta1-ounass-jarvis.atg.digital/* | Host | | Host permission — access limited to this URL pattern. |
| https://preprod-ounass-jarvis.atg.digital/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.atg.digital/* | Host | | Host permission — access limited to this URL pattern. |
| Early Content Script Execution | Risk Factor | | This extension runs content scripts at document_start. |
| windows | Permission | Unknown | No classification available for this permission. |