@cws-check/cli
v0.1.0
Published
Static compliance checker for Chrome Web Store policy — Manifest V3, Limited-Use data, remote code, MV2 deprecation.
Maintainers
Readme
cws-check
Static compliance checker for Chrome Web Store policy. Point it at an
extension's source directory; it reads manifest.json and scans bundled
JS/HTML for patterns that draw CWS review rejections or trip the policy
changes enforced 2026-08-01 and 2026-08-31 (see
../../research/findings/l4-2026-08-03.md).
Runs entirely locally, offline, read-only. It never transmits the
extension it scans anywhere — the tool's own risk profile is why it was
built first out of the portfolio (see ../../ideas/ideas.yaml,
extension-compliance-helper).
What it checks
- manifest_version — flags MV2, with a countdown to the 2026-08-31 Chrome Web Store removal date.
- remote-code —
eval,new Function, remoteimportScripts, remote<script src>tags: MV3's hard ban on executing code outside the package. - sensitive-permissions — permissions that draw reviewer scrutiny
(
cookies,history,tabs,webRequest,geolocation,management,debugger,downloads,browsingData) and<all_urls>-style broad host access, flagged for a matching CWS listing disclosure. - csp —
content_security_policyoverrides that re-enableunsafe-evalorunsafe-inline. - guardrail-keywords — heuristic scan for language matching the two bans added 2026-08-01: AI-guardrail/usage-limit bypass, and real-money prediction markets. Blunt on purpose; read every hit yourself.
- single-purpose — metadata completeness only (missing description, high permission count as a scope-creep proxy). Cannot judge intent — a human still has to confirm the feature set matches one stated purpose.
Use
node src/cli.js path/to/extension
node src/cli.js path/to/extension --md report.md # also write a markdown reportExit code is 1 if any check fails (CI-friendly), 0 otherwise. Warnings
never fail the exit code — they're judgment calls, not hard blockers.
Licensing model
(This section is about the paid --watch feature's license keys — the
code itself is MIT, see LICENSE.)
All six compliance checks are free, forever. The paid tier adds
--watch, which cross-references your findings against dated CWS policy
changes so you learn which ones are time-sensitive without having to
monitor Chrome's policy blog yourself.
cws-check license activate <key>
cws-check license status
cws-check path/to/extension --watchLicenses are Ed25519-signed and verified offline — there is no license server, and the tool never phones home. The published package contains only a public key, which can verify a signature but cannot create one, so forging a license is not possible even though the source is open. (A shared-secret scheme would be trivially breakable here, since anyone can read the published source.)
Honest limits, documented rather than hidden: there's no activation cap
and no revocation — a shared key works anywhere until it expires. See
admin/README.md for why those trade-offs were chosen. The paid value is
the maintained policy feed, not the code.
Test
npm testtest/fixtures/clean-extension should report 0 warn / 0 fail.
test/fixtures/violating-extension deliberately trips every check.
What this is not
Not a substitute for reading your own CWS listing's data-disclosure form, and not a guarantee of review approval — it catches known patterns, not reviewer judgment calls. It has never been validated against an actual Chrome Web Store review outcome, because no extension has been submitted using it yet; the checks encode documented policy, not observed reviewer behavior.
