Guides authorized reverse engineering of Chrome and Firefox browser extensions, from manifest analysis to background worker logic.
- What it does
- This skill provides a structured workflow for analyzing browser extension packages (crx, xpi, or unpacked directories). It covers unpacking the extension, reading manifest.json permissions and entry points, tracing service worker and content script logic, and inspecting storage, network, and message-passing hooks. It also lists tooling such as DevTools, YARA, and related reverse-engineering skill chains, and ends with a self-check list.
- When to use it
- Use it when investigating Chrome, Edge, or Firefox extensions, including malicious extension IOC or supply-chain poisoning cases, or when recovering signing, encryption, or proxy logic implemented inside an extension. It is intended for authorized reverse engineering, not for ordinary web page JavaScript.
- Requirements
- Instructions only; no scripts are shipped. It references a companion file references/extension-analysis.md and sibling skills (js-reverse, malware-analysis, field-journal). Practical use involves unpacking tools, jq, Chrome DevTools, and optionally YARA or Frida/CDP tooling.