Extensions are .catplug packages with JavaScript code run by QuickJS 2026-06-04, embedded through JNI in an isolated Android service. Every extension has its own environment, its own SQLite data and its own permissions.
What an extension can do #
- Observe requests and responses with
cat.events.on. - Change messages before they are forwarded with
cat.proxy.onRequestandcat.proxy.onResponse. - Send requests to declared destinations with
cat.http.send. - Call external APIs with protected credentials using
cat.external.call. - Register commands, message menus and native tabs.
- Store data and record findings with evidence.
- Take part in visual workflows as steps and parsers.
What an extension cannot do #
There is no Node.js, DOM, fetch, general file access or process execution. Use cat.http.parseUrl for URLs and cat.bytes for UTF-8 conversion. TLS uses Android certificate validation and the SDK cannot disable it.
Integration points #
Hooks cover the proxy, Network Proxy, Repeater, Intruder and Discoverer. Every message reports its origin in source:
source | Origin |
|---|---|
proxy | Intercepted browser traffic |
network_proxy | Network Proxy session |
repetir | Repeater sends |
intruso | Intruder sends |
descobridor | Discoverer sends |
extension | Requests sent by extensions |
laboratory | Simulated laboratory traffic |
Requests from an extension never return to its own handlers; other extensions may process them according to their scope. When extensions process proxy traffic, applicable replacement rules run before the handlers, and manual editing takes precedence.
Lifecycle #
- Create or import — in Settings → Extensions, use Create (basic template or the Aurora example), import a
.catplugor build the package in the web IDE or in CatSuite Studio for VS Code. - Validate — package, manifest and code are validated before anything is replaced.
- Approve — installs start disabled. When enabling, you review capabilities and destinations.
- Run — hooks, commands, menus and tabs come alive.
- Update — broader permissions or destinations require new approval.
API v1 limits #
| Resource | Limit |
|---|---|
| Active extensions | 4 |
| Memory per environment | 32 MiB |
| Mutation handler | 100 ms, synchronous |
| Concurrent HTTP calls | 2 per extension |
| Total HTTP timeout | 120 seconds |
| HTTP response | up to 8 MiB, with a preview for JavaScript |
| Editable preview | up to 32 KiB |
| Entry script | up to 128 KiB |
| Package | 10 MiB compressed, 40 MiB expanded and 500 files |
| Data per extension | 10 MiB, with 128 KiB per value |
Larger, incomplete, compressed or continuous bodies are read-only. SSE and WebSocket keep their transport, and HTTPS tunnels without decryption do not provide HTTP content.
Your first extension #
cat.commands.register('lab.hello', {'pt-BR': 'Dizer olá', en: 'Say hello'}, () => {
cat.log({'pt-BR': 'Olá do laboratório.', en: 'Hello from the lab.'});
return {ok: true};
});Declare the commands permission in the manifest and run the command in the simulator of the extension IDE.