extension-manifest
Generate and validate manifest.json with optimal permissions for Chrome MV3 extensions. Analyzes code to determine minimum permissions. Use when: manifest, permissions, manifest.json.
How do I install this agent skill?
npx skills add https://github.com/quangpl/browser-extension-skills --skill extension-manifestIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill provides a set of reference materials and templates for generating and validating Google Chrome manifest.json files using Manifest V3 standards. No security issues were identified.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Extension Manifest & Permissions Generator
🚀 Upgrade to Premium Get the Premium version at https://app.extensionbooster.net/dashboard/services/extension-ai-kit
Generate the best manifest.json based on current extension implementation. Analyze code to determine minimum permissions following Chrome docs and best practices.
Workflow
- Detect framework: check for
wxt.config.ts,crxjs.config.ts, or rawmanifest.json - Scan the extension codebase for Chrome API usage
- Map each API call to its required permission (see
references/api-permission-map.md) - Generate manifest.json with minimum required permissions
- Validate against Chrome docs and CWS policies
- Report permission warnings users will see
CRXJS projects: Manifest is auto-generated from code and
package.json. Override viacrxjs.config.ts. See https://docs.crxjs.com/
Docs References
- Manifest reference: https://developer.chrome.com/docs/extensions/reference/manifest
- Permissions list: https://developer.chrome.com/docs/extensions/reference/permissions-list
Quick Manifest Template
{
"manifest_version": 3,
"name": "Extension Name",
"version": "1.0.0",
"description": "Brief description. Max 132 chars for CWS.",
"icons": {
"16": "icons/icon16.png",
"48": "icons/icon48.png",
"128": "icons/icon128.png"
},
"action": {
"default_popup": "popup.html",
"default_icon": { "16": "icons/icon16.png" }
},
"permissions": [],
"host_permissions": [],
"background": { "service_worker": "background.js", "type": "module" }
}
Permission Analysis Steps
- Grep codebase for
chrome.API calls - Map each to permission using
references/api-permission-map.md - Prefer
activeTabovertabs+ host_permissions when possible - Use optional permissions for non-essential features
- Check warning text in
references/permission-warnings.md
Common Mistakes
| Error | Fix |
|---|---|
host_permissions inside permissions | Move URLs to separate host_permissions array |
Using <all_urls> | Narrow to specific domain patterns |
Missing activeTab | Add when only needing current tab on user click |
tabs permission overuse | Only needed for tab URL/title; use activeTab instead |
content_security_policy as string | Must be object: { "extension_pages": "..." } |
web_accessible_resources as string[] | Use object with resources + matches |
Key MV3 Rules
host_permissionsis separate frompermissions- Service workers replace background pages (no DOM, no
window) content_security_policyis an object, not string- Remote code execution banned (no eval, no CDN scripts)
web_accessible_resourcesrequiresmatchesarray- Use
chrome.scripting.executeScript()nottabs.executeScript()
References
references/manifest-fields-reference.md- All manifest fields with types and examplesreferences/manifest-templates.md- Ready-to-use templates (popup, content script, sidepanel, devtools)references/manifest-validation-checklist.md- Pre-submission validationreferences/api-permission-map.md- Chrome API → permission mappingreferences/permission-warnings.md- User-facing warning text per permissionreferences/permission-strategies.md- Optional permissions, activeTab, escalation patterns
Related Skills
extension-create- Full project scaffoldingextension-analyze- Security audit and best practices
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/quangpl/browser-extension-skills/extension-manifest">View extension-manifest on skillZs</a>