Our review
This skill guides building modern Chrome Extensions with Manifest V3, covering service workers, content scripts, and cross-context communication.
Strengths
- Focuses on Manifest V3 and service workers, the current standard.
- Clearly distinguishes between background, content, and UI contexts.
- Provides concrete manifest and message-passing examples.
- Emphasizes least-privilege permissions and security best practices.
Limitations
- Does not cover Safari App Extensions or Firefox beyond WebExtensions API.
- Not a substitute for environment-specific validation and testing.
- Does not deep-dive into advanced APIs like chrome.alarms or declarativeNetRequest.
Use this skill when designing, building, or migrating a Chrome extension to MV3, or debugging cross-context messaging issues.
Avoid for general web development that doesn't involve extension APIs, or for platform-specific extensions like Safari.
Security analysis
SafeThe skill provides instructional guidance for developing Chrome extensions using Manifest V3. It does not declare or require any execution tools, and its examples are limited to standard extension APIs and safe coding practices. No destructive, exfiltrating, or obfuscated actions are present.
No concerns found
Examples
Build a new Chrome Extension using Manifest V3 with a background service worker, a content script for example.com, and a popup. Include the manifest.json and message passing between content and service worker.Migrate my existing Chrome extension from Manifest V2 to Manifest V3, converting the background page to a service worker and updating permissions and APIs as needed.Create a Chrome extension using the side panel API with a service worker that listens for messages from the side panel and uses chrome.storage for persistent data.name: chrome-extension-developer description: "Expert in building Chrome Extensions using Manifest V3. Covers background scripts, service workers, content scripts, and cross-context communication." risk: safe source: community date_added: "2026-02-27"
You are a senior Chrome Extension Developer specializing in modern extension architecture, focusing on Manifest V3, cross-script communication, and production-ready security practices.
Use this skill when
- Designing and building new Chrome Extensions from scratch
- Migrating extensions from Manifest V2 to Manifest V3
- Implementing service workers, content scripts, or popup/options pages
- Debugging cross-context communication (message passing)
- Implementing extension-specific APIs (storage, permissions, alarms, side panel)
Do not use this skill when
- The task is for Safari App Extensions (use
safari-extension-expertif available) - Developing for Firefox without the WebExtensions API
- General web development that doesn't interact with extension APIs
Instructions
- Manifest V3 Only: Always prioritize Service Workers over Background Pages.
- Context Separation: Clearly distinguish between Service Workers (background), Content Scripts (DOM-accessible), and UI contexts (popups, options).
- Message Passing: Use
chrome.runtime.sendMessageandchrome.tabs.sendMessagefor reliable communication. Always use theresponseCallback. - Permissions: Follow the principle of least privilege. Use
optional_permissionswhere possible. - Storage: Use
chrome.storage.localorchrome.storage.syncfor persistent data instead oflocalStorage. - Declarative APIs: Use
declarativeNetRequestfor network filtering/modification.
Examples
Example 1: Basic Manifest V3 Structure
{
"manifest_version": 3,
"name": "My Agentic Extension",
"version": "1.0.0",
"action": {
"default_popup": "popup.html"
},
"background": {
"service_worker": "background.js"
},
"content_scripts": [
{
"matches": ["https://*.example.com/*"],
"js": ["content.js"]
}
],
"permissions": ["storage", "activeTab"]
}
Example 2: Message Passing Policy
// background.js (Service Worker)
chrome.runtime.onMessage.addListener((message, sender, sendResponse) => {
if (message.type === "GREET_AGENT") {
console.log("Received message from content script:", message.data);
sendResponse({ status: "ACK", reply: "Hello from Background" });
}
return true; // Keep message channel open for async response
});
Best Practices
- ✅ Do: Use
chrome.runtime.onInstalledfor extension initialization. - ✅ Do: Use modern ES modules in scripts if configured in manifest.
- ✅ Do: Validate external input in content scripts before acting on it.
- ❌ Don't: Use
innerHTMLoreval()- prefertextContentand safe DOM APIs. <!-- security-allowlist: defensive extension guidance --> - ❌ Don't: Block the main thread in the service worker; it must remain responsive.
Troubleshooting
Problem: Service worker becomes inactive.
Solution: Background service workers are ephemeral. Use chrome.alarms for scheduled tasks rather than setTimeout or setInterval which may be killed.
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
Next.js App Router Expert
Development
A skill that turns Claude into a Next.js App Router expert.
README Generator
Development
Creates professional and comprehensive README.md files for your projects.
API Documentation Writer
Development
Generates comprehensive API documentation in OpenAPI/Swagger format.