| declarativeNetRequest | Permission | | This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites. |
| identity | Permission | | This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service. |
| downloads | Permission | | This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns. |
| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact• 10% increase: Early script execution enables pre-emptive content manipulation |
| tabs | Permission | | This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns. |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| unlimitedStorage | Permission | | This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data. |
| *://lemida.biu.ac.il/* | Host | | Host permission — access limited to this URL pattern. |
| *://js.nagich.co.il/* | Host | | Host permission — access limited to this URL pattern. |
| *://access.nagich.co.il/* | Host | | Host permission — access limited to this URL pattern. |
| *://enterprise.nagich.co.il/* | Host | | Host permission — access limited to this URL pattern. |
| *://cdn.jsdelivr.net/* | Host | | Host permission — access limited to this URL pattern. |
| *://fonts.googleapis.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://fonts.gstatic.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://www.google-analytics.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://www.googletagmanager.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://axt1t2yu790u.compat.objectstorage.il-jerusalem-1.oraclecloud.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://objectstorage.il-jerusalem-1.oraclecloud.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://login.microsoftonline.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://graph.microsoft.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://connect.facebook.net/* | Host | | Host permission — access limited to this URL pattern. |
| *://stats.biu.ac.il/* | Host | | Host permission — access limited to this URL pattern. |
| Access to Sensitive Domains | Risk Factor | | This extension requests access to sensitive domains: *://fonts.googleapis.com/*, *://www.google-analytics.com/*, *://www.googletagmanager.com/*, *://connect.facebook.net/* |
| Early Content Script Execution | Risk Factor | | This extension runs content scripts at document_start. |
| alarms | Permission | | This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data. |