Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Extensions

CatSuite extensions

How .catplug extensions work: isolated QuickJS engine, permissions, lifecycle, integration points and API v1 limits.

3 min read

Extensions are .catplug packages with JavaScript code run by QuickJS 2026-06-04, embedded through JNI in an isolated Android service. Every extension has its own environment, its own SQLite data and its own permissions.

What an extension can do #

  • Observe requests and responses with cat.events.on.
  • Change messages before they are forwarded with cat.proxy.onRequest and cat.proxy.onResponse.
  • Send requests to declared destinations with cat.http.send.
  • Call external APIs with protected credentials using cat.external.call.
  • Register commands, message menus and native tabs.
  • Store data and record findings with evidence.
  • Take part in visual workflows as steps and parsers.

What an extension cannot do #

There is no Node.js, DOM, fetch, general file access or process execution. Use cat.http.parseUrl for URLs and cat.bytes for UTF-8 conversion. TLS uses Android certificate validation and the SDK cannot disable it.

Integration points #

Hooks cover the proxy, Network Proxy, Repeater, Intruder and Discoverer. Every message reports its origin in source:

sourceOrigin
proxyIntercepted browser traffic
network_proxyNetwork Proxy session
repetirRepeater sends
intrusoIntruder sends
descobridorDiscoverer sends
extensionRequests sent by extensions
laboratorySimulated laboratory traffic

Requests from an extension never return to its own handlers; other extensions may process them according to their scope. When extensions process proxy traffic, applicable replacement rules run before the handlers, and manual editing takes precedence.

Lifecycle #

  1. Create or import — in Settings → Extensions, use Create (basic template or the Aurora example), import a .catplug or build the package in the web IDE or in CatSuite Studio for VS Code.
  2. Validate — package, manifest and code are validated before anything is replaced.
  3. Approve — installs start disabled. When enabling, you review capabilities and destinations.
  4. Run — hooks, commands, menus and tabs come alive.
  5. Update — broader permissions or destinations require new approval.

API v1 limits #

ResourceLimit
Active extensions4
Memory per environment32 MiB
Mutation handler100 ms, synchronous
Concurrent HTTP calls2 per extension
Total HTTP timeout120 seconds
HTTP responseup to 8 MiB, with a preview for JavaScript
Editable previewup to 32 KiB
Entry scriptup to 128 KiB
Package10 MiB compressed, 40 MiB expanded and 500 files
Data per extension10 MiB, with 128 KiB per value

Larger, incomplete, compressed or continuous bodies are read-only. SSE and WebSocket keep their transport, and HTTPS tunnels without decryption do not provide HTTP content.

Your first extension #

main.jsJavaScript
cat.commands.register('lab.hello', {'pt-BR': 'Dizer olá', en: 'Say hello'}, () => {
  cat.log({'pt-BR': 'Olá do laboratório.', en: 'Hello from the lab.'});
  return {ok: true};
});

Declare the commands permission in the manifest and run the command in the simulator of the extension IDE.

Keep going #