Extensions

Understand Extension permissions

Review requested project, file, model, connected-app, command, skill, and automation capabilities before approval.

8 min readIntermediateUpdated 2026-07-29For LobeWork 1.0+
01

Permissions describe contribution intent

A manifest can request capabilities such as reading project metadata, registering a command, or contributing a provider definition.

02

Permission approval is explicit

Install and update flows should show new or changed permissions instead of preserving approval silently.

03

Plan and access checks still apply

Extension permissions cannot bypass server-provided LobeWork access, organization policy, or other authorization checks.

04

Source trust matters

Official, third-party, and local sources remain visible. Verified publisher status does not remove the need to review permissions.

05

Current permissions do not enable arbitrary code

The LobeWork v1 release is manifest-only; permission labels do not create a hidden JavaScript, native, shell, or installer execution path.

NEED A GUIDED ANSWER?

Ask LobeWork about this guide.

Ask LobeWork uses the same published article library and links back to its source guidance.

WAS THIS GUIDE HELPFUL?Help us improve the documentation.