PermiScope

PermiScope is a web app plus a lightweight CLI that scans your ecosystem for risky plugin and extension permissions before they become an incident. It targets platforms where extensions quietly accumulate access (VS Code, JetBrains, Chrome/Edge, Slack apps, GitHub Apps). It inventories installed plugins across teams, normalizes their declared permissions/scopes, and flags over-privileged or newly expanded access after updates. Admins get a simple risk dashboard, policy rules (e.g., “no clipboard access,” “no repo write without approval”), and an approval workflow that integrates with existing IAM and ticketing. This is not a magical security product: it won’t stop every attack, and it can’t see inside every closed-source extension. But it will reliably reduce blind spots, catch permission creep, and create an auditable trail for compliance and procurement reviews.

← Back to idea list