← Home

@opentabs-dev/browser-extension

Chrome extension that bridges AI agents to web applications through the user's authenticated browser session

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

opentabs-dev-admin

Keywords

opentabsmcpmodelcontextprotocolai-agentbrowserchrome-extensionmanifest-v3browser-automation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@radix-ui/react-dialog AI (phantom-deps): Config-referenced UI component; stable pattern for this package type. ai
phantom-deps phantom-dep:@radix-ui/react-visually-hidden AI (phantom-deps): Config-referenced UI component; stable pattern for this package type. ai
phantom-deps phantom-dep:tw-animate-css AI (phantom-deps): Declared in dependencies; phantom-dep heuristic false positive for CSS utility packages. ai
bogus-package bogus-package AI (bogus-package): Scoped internal package; missing metadata is expected and not indicative of malice. ai

Versions (showing 51 of 77)

View all versions
Version Deps Published
0.0.115 16 / 13
0.0.109 16 / 13
0.0.108 16 / 13
0.0.107 16 / 13
0.0.106 16 / 13
0.0.105 16 / 13
0.0.104 16 / 13
0.0.103 16 / 13
0.0.102 16 / 13
0.0.101 16 / 13
0.0.100 16 / 13
0.0.99 16 / 13
0.0.98 16 / 13
0.0.97 16 / 13
0.0.96 16 / 13
0.0.95 16 / 13
0.0.94 16 / 13
0.0.93 16 / 13
0.0.92 16 / 13
0.0.91 16 / 13
0.0.90 16 / 13
0.0.89 16 / 13
0.0.88 16 / 13
0.0.87 16 / 13
0.0.86 16 / 13
0.0.85 16 / 13
0.0.84 16 / 13
0.0.83 16 / 13
0.0.82 16 / 13
0.0.81 16 / 12
0.0.80 16 / 12
0.0.79 16 / 12
0.0.78 16 / 12
0.0.77 16 / 12
0.0.76 16 / 12
0.0.75 16 / 12
0.0.74 16 / 12
0.0.73 16 / 12
0.0.72 16 / 12
0.0.71 16 / 12
0.0.70 16 / 12
0.0.69 16 / 12
0.0.68 16 / 12
0.0.67 16 / 12
0.0.66 16 / 12
0.0.65 16 / 12
0.0.64 16 / 12
0.0.63 16 / 11
0.0.62 16 / 11
0.0.61 15 / 11
0.0.60 15 / 11

v0.0.115

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: opentabs-dev-admin → GitHub Actions (on 2026-07-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (opentabs-dev-admin) on 2026-07-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.