
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@extension.dev/mcp
Advanced tools
MCP server that lets AI agents (Claude Code, Claude Desktop, Cursor, Copilot, Codex) build, run, inspect, and publish browser extensions. 33 tools for scaffolding, live DOM inspection, log streaming, and store-ready builds across Chrome, Edge, Firefox, Sa
Give your AI agent hands for browser extension development. 33 MCP tools that scaffold, run, inspect, debug, and publish cross-browser extensions.
claude mcp add extension-dev npx @extension.dev/mcp
Works with Claude Code, Claude Desktop, Cursor, and any MCP client.
extension.dev · Documentation · Templates · Examples · Discord
Extensions fail silently: content scripts that never inject, panels that never open, permissions that return undefined with no error. An agent editing files blind will happily "fix" all of them without noticing none of them work.
These tools give agents eyes on the live browser, so they debug from evidence instead of guessing:
chrome.storage contents, and the loaded-extension listBuilt on Extension.js, the open-source cross-browser extension framework.
| Claude Code | Claude Desktop | Cursor |
claude mcp add extension-dev npx @extension.dev/mcp
Or install it as a plugin, the MCP server plus the /extension, /extension-add, /extension-debug, and /extension-publish commands in one step:
/plugin marketplace add extensiondev/mcp
/plugin install extension-mcp@extensiondev-mcp
.mcp.json{
"mcpServers": {
"extension-dev": {
"command": "npx",
"args": ["@extension.dev/mcp"]
}
}
}
This server gives agents hands; @extension.dev/skill gives them judgment: the cross-browser rules, silent-failure gotchas, debugging playbooks, and store checklist, packaged in the open Agent Skills format. With both installed, agents know to verify against the live browser instead of guessing, and these tools make that a one-call operation.
npm i -D @extension.dev/skill
mkdir -p .claude/skills && cp -R node_modules/@extension.dev/skill/skills/extension-dev .claude/skills/
The package ships drop-in instructions, slash commands, and rules for extension projects:
# Rules (how Claude understands your project)
cp node_modules/@extension.dev/mcp/claude/CLAUDE.md ~/my-extension/.claude/CLAUDE.md
# Slash commands (/extension, /extension-add, /extension-debug, /extension-publish)
mkdir -p ~/my-extension/.claude/commands
cp node_modules/@extension.dev/mcp/claude/commands/*.md ~/my-extension/.claude/commands/
| Tier | Tool | Description |
|---|---|---|
| build | extension_create | Scaffold from a template |
| build | extension_list_templates | Browse 60+ templates |
| build | extension_get_template_source | Read template source files |
| build | extension_add_feature | Add sidebar/popup/content script |
| build | extension_build | Build for production |
| run | extension_dev | Dev server with HMR |
| run | extension_start | Build + preview |
| run | extension_preview | Preview the production build |
| run | extension_wait | Poll the dev-server ready contract |
| run | extension_stop | Stop a dev/start/preview session (server + browser) |
| see | extension_manifest_validate | Cross-browser manifest validation |
| see | extension_inspect | Build output analysis |
| see | extension_source_inspect | Live DOM inspection (CDP) |
| see | extension_dom_inspect | CDP-free DOM snapshot |
| see | extension_list_extensions | List loaded extensions (Chromium) |
| see | extension_logs | Stream logs from every context |
| see | extension_doctor | Diagnose the dev session leg by leg (ready contract, ports, token, executor, browser) |
| act | extension_eval | Evaluate in a context (needs allowEval: true on extension_dev) |
| act | extension_storage | Read/write chrome.storage |
| act | extension_reload | Reload extension or tab |
| act | extension_open | Open a surface / trigger action, command |
| browsers | extension_install_browser | Install a managed browser binary |
| browsers | extension_uninstall_browser | Remove a managed browser binary |
| browsers | extension_list_browsers | List managed browsers |
| browsers | extension_detect_browsers | Detect system browsers |
| platform | extension_login | GitHub device-code login, stored token |
| platform | extension_whoami | Show the stored login (never the token) |
| platform | extension_logout | Remove stored credentials |
| platform | extension_publish | Publish a shareable preview to extension.dev |
| platform | extension_release_promote | Promote a build to a release channel, headless |
| platform | extension_deploy | Submit to the Chrome, Firefox, and Edge stores through extension.dev |
Browser-launching tools (dev, start, preview) shell out to the extension CLI, the project's own node_modules/.bin/extension when present, otherwise npx extension@<pinned> at the version this package is verified against; everything else runs in-process.
The platform tools connect agents to extension.dev: extension_login runs a GitHub device-code flow and stores a project-scoped token locally (never returned to the agent), extension_publish turns a build into a shareable preview URL, and extension_release_promote promotes a tested build to a release channel from CI or an agent session, no browser required. extension_deploy submits a built extension to the Chrome Web Store, Edge Add-ons, and Firefox AMO through extension.dev, which holds your store credentials and dispatches the release from your project's mirror CI, it defaults to a dry run and store credentials are never tool arguments. After a real submission, extension_store_status reads the recorded outcome, per-store credential health, and review state from the project's public registry, so agents and CI can answer "was it approved?" without a console visit. Access tokens live at most 7 days; CI pipelines re-mint them from the console's Access tokens page.
| Package | Use it to |
|---|---|
@extension.dev/skill | Teach AI agents the judgment half: cross-browser rules, gotchas, playbooks |
@extension.dev/artifact-integrity | Verify extension artifacts and gate CI on tampered bytes before they ship |
All of it rides on Extension.js, the open-source cross-browser extension framework.
Apache-2.0 (c) 2026 Cezar Augusto and the extension.dev collaborators. See LICENSE.
FAQs
MCP server that lets AI agents (Claude Code, Claude Desktop, Cursor, Copilot, Codex) build, run, inspect, and publish browser extensions. 28 tools for scaffolding, live DOM inspection, log streaming, and store-ready builds across Chrome, Edge, Firefox, Sa
The npm package @extension.dev/mcp receives a total of 931 weekly downloads. As such, @extension.dev/mcp popularity was classified as not popular.
We found that @extension.dev/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.