Start here
The free tool below runs entirely in this browser — no account, nothing stored or transmitted. Redact anything you would not want kept before you type it.
Open the companion tool →Why the permission list is the reading
A browser extension that "reads and changes all your data on all websites" can watch every page you open and send that text to a model. The permission list is public, shown by the browser, and ignored by almost everyone.
The audit is not about distrusting the developer — it is about the minimum necessary: an extension that only needs to work on one site should not have all-sites access, and one that claims privacy should not also ask to read everything.
The protocol
- Open the extension's detail page and list the permissions the browser reports.
- Read the plain-language audit: what each permission allows in practice.
- Compare it to what the extension actually needs to do its job.
- Trim what you can in settings, or replace an over-permissioned extension with a narrower one.
What the tool does
List an extension's permissions and get a plain-language audit of what each allows. It runs in this browser; nothing is sent or stored.
Limit first: This is a permission-reading aid, not security software and not a guarantee about any extension's behavior. Verify against the current permission list in your browser.
Open the companion tool →One human next step
Trim the extension's site access in browser settings, or remove it if the permissions outrun its purpose. Report deceptive extensions to the platform and the FTC.
Research log and safety checks
AI-assist path: not applicable — the permission list is already in plain view; the artifact is the translation and the trim checklist, not a model judgment. §6.10: not a frontier-pace topic.
§0.5 protection result: category is data-privacy-exposure; crisis-adjacent: no; fear/urgency/scarcity toolkit used: no. The protective function is free and the paid feature is convenience only.