Extensions

Why Extensions are manifest-only today

Understand the current no-code-execution boundary and what a future trusted runtime would require.

9 min readAdvancedUpdated 2026-07-29For LobeWork 1.0+
01

Current boundary

LobeWork stores validated manifests, permissions, versions, publisher state, accesss, and contribution metadata.

02

Blocked execution paths

Third-party JavaScript, native modules, shell commands, package installers, and remote scripts are not executed.

03

Future package trust

Executable packages would require signatures, immutable hashes, publisher identity, revocation, advisories, and rollback.

04

Future process isolation

A sandboxed host, capability-scoped IPC, crash isolation, resource limits, and restricted filesystem and network access would be required.

05

Developer mode remains deliberate

Local-manifest testing should never silently weaken production security or convert an untrusted package into an official publisher.

NEED A GUIDED ANSWER?

Ask LobeWork about this guide.

Ask LobeWork uses the same published article library and links back to its source guidance.

WAS THIS GUIDE HELPFUL?Help us improve the documentation.