I shipped Chrome extensions with an empty permissions list. Here is what that costs you.
Every Chrome extension I install asks for something. Read and change all your data on all websites, usually. So when I built five small developer utilities as extensions, I wanted to know how far I could get with the permissions array empty. All five shipped with this: { "manifest_version" : 3 , "name" : "Base64 Encoder & Decoder" , "version" : "1.0.0" , "description" : "..." , "icons" : { "16" :…
Building small developer tools as Chrome extensions allowed me to explore the impact of empty permissions. All five extensions were shipped with an empty permissions array, meaning no access to the current page, storage, or clipboard. Three main capabilities were sacrificed: the ability to read the selected text or URL, preserving state between sessions, and clipboard functionality.
Despite these limitations, the extensions primarily relied on normal web page functionalities such as Web Crypto, TextEncoder, and DOM APIs. No external requests or network operations were made. No code from npm was bundled, and all tools were hand-written. This approach led to a few hundred lines of custom code for each extension, resulting in each zip file being around 16 KB.
The source code that reviewers see is the same that ships, meaning there's no hidden transitive dependency tree. The tradeoff was worth it for these simple tools, but for more complex applications, a dependency would be preferable to avoid potential bugs and maintain review efficiency.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.