| scripting | Permission | | This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to. |
| debugger | Permission | | This permission grants the extension ability to debug and control other extensions and browser tabs. Rated Critical because it can access and modify other extensions' internal state, inject code, and access sensitive data from any tab. |
| <all_urls> | Host | | Broad host access β the extension can read/modify content on every website. |
| identity | Permission | | This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service. |
| offscreen | Permission | | This permission creates hidden browser documents with full DOM access. Rated High because it can run background operations invisibly, potentially executing malicious code without user awareness. |
| nativeMessaging | Permission | | This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files. |
| clipboardWrite | Permission | | This permission allows modification of clipboard content. Rated High because it can inject malicious content into the clipboard, modify copied passwords, and manipulate copied data. |
| downloads | Permission | | This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns. |
| webNavigation | Permission | | This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities. |
| history | Permission | | This permission grants access to your complete browsing history. Rated High because it can track all visited websites, reveal sensitive browsing patterns, and expose private information. |
| sessions | Permission | | This permission accesses recently closed tabs and windows. Rated High because it can monitor user activity, recover closed sensitive pages, and track browsing patterns. |
| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:β’ 20% increase: Access to sensitive domains increases potential impact |
| Broad Host Permissions | Risk Factor | | This extension has broad host permissions allowing it to access many or all websites. |
| Broad Content Script Access | Risk Factor | | This extension can inject scripts into any website. |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| activeTab | Permission | | This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions. |
| tabs | Permission | | This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns. |
| tabGroups | Permission | | This permission manages tab grouping functionality. Rated Medium because it can monitor tab organization, track user workflow patterns, and modify tab relationships. |
| https://server.app.matrxserver.com/* | Host | | Host permission β access limited to this URL pattern. |
| https://staging.server.app.matrxserver.com/* | Host | | Host permission β access limited to this URL pattern. |
| https://dev.server.app.matrxserver.com/* | Host | | Host permission β access limited to this URL pattern. |
| http://localhost:8000/* | Host | | Host permission β access limited to this URL pattern. |
| https://*.aimatrx.com/* | Host | | Host permission β access limited to this URL pattern. |
| https://txzxabzwovsujtloxrus.supabase.co/* | Host | | Host permission β access limited to this URL pattern. |
| http://127.0.0.1:22180/* | Host | | Host permission β access limited to this URL pattern. |
| Access to Sensitive Domains | Risk Factor | | This extension requests access to sensitive domains: https://staging.server.app.matrxserver.com/* |
| sidePanel | Permission | | This permission adds custom panels to the browser interface. Rated Low because it only affects browser UI elements and cannot access page content. |
| alarms | Permission | | This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data. |
| contextMenus | Permission | | This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content. |
| bookmarks | Permission | | This permission manages browser bookmarks and folders. Rated Low because it can only modify bookmark data, which is not sensitive and changes are visible to users. |
| notifications | Permission | | This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data. |