Security model

The extension reduces access and stops processing on sensitive surfaces.

Packaged code

Manifest V3. No remote JavaScript, remote WebAssembly, eval, advertising, or analytics.

Sensitive surfaces

Known login, account, billing, payment, subscription, and checkout routes are blocked. Visible password, one-time-code, and card fields suspend the extension.

Password-manager neutrality

The extension does not disable, detect, or modify password-manager applications. Internal passphrase fields use neutral autocomplete settings and remain paste-enabled.

Local Bridge

Fixed loopback endpoint, one-time pairing, exact extension origin, short-lived sessions, no file, shell, URL-fetch, or model-install API.

Secrets

API keys are not stored in Chrome Sync. Session storage is the default; optional persistent storage is encrypted locally and requires a passphrase after restart.

No absolute guarantee

No software can guarantee complete security. Keep Chrome and the operating system updated and report suspected issues promptly.

Report a security issue

نموذج الأمان

تقلل الإضافة الوصول وتتوقف عن المعالجة عند ظهور أسطح حساسة.

كود مرفق

Manifest V3، دون JavaScript أو WebAssembly بعيد، ودون eval أو إعلانات أو تحليلات.

الأسطح الحساسة

تُحظر مسارات تسجيل الدخول والحساب والفوترة والدفع والاشتراك وإتمام الشراء، وتتوقف الإضافة عند ظهور حقول كلمة مرور أو رمز تحقق أو بطاقة.

الحياد تجاه مديري كلمات المرور

لا تعطل الإضافة تطبيقات إدارة كلمات المرور ولا تكتشفها أو تعدلها. حقول عبارة المرور الداخلية محايدة وتسمح باللصق.

Local Bridge

عنوان loopback ثابت، اقتران لمرة واحدة، Origin مطابق للإضافة، جلسات قصيرة، ودون واجهات ملفات أو أوامر أو جلب روابط أو تثبيت نماذج.

الأسرار

لا تُحفظ مفاتيح API في Chrome Sync. تخزين الجلسة هو الافتراضي، والحفظ الدائم الاختياري مشفر محلياً ويتطلب عبارة مرور بعد إعادة التشغيل.

لا ضمان مطلق

لا يستطيع أي برنامج ضمان الأمان الكامل. حافظ على تحديث Chrome ونظام التشغيل وأبلغ عن أي مشكلة مشتبه بها.

الإبلاغ عن مشكلة أمنية