You'll notice
No documentation found
Browser-extension access is now also checked by the general MCP/tool permission-scope gate.
Browser-extension connections are now denied by the generic MCP/tool scope-permission check (Ah) when they don't come from the SDK, independent of the existing scope allowlist. This closes off a path that previously wasn't checked against the allow_claude_browser_extension gate.
Names in the bundleallow_claude_browser_extension