Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Extensions

The .catplug package manifest

Structure of the .catplug file, manifest.json fields, validation rules, permissions, destinations, SHA-256 hashes and format 2.

4 min read

Package structure #

A .catplug is a ZIP file with manifest.json at the root and the files listed in hashes.

Text
auditor.catplug
├── manifest.json
├── main.js
├── fixtures.json
├── README.pt-BR.md
└── README.en.md

Complete example #

manifest.jsonJSON
{
  "formatVersion": 1,
  "apiVersion": 1,
  "id": "lab.auditor",
  "version": "1.0.0",
  "author": "NetCatTest",
  "entry": "main.js",
  "name": {"pt-BR": "Auditor de respostas", "en": "Response auditor"},
  "description": {"pt-BR": "Audita cabeçalhos de cache.", "en": "Audits cache headers."},
  "permissions": ["traffic.read", "traffic.modify", "findings", "commands", "ui.tab"],
  "targets": ["api.aurora.test"],
  "externalHosts": [],
  "settings": {"laboratory": true},
  "hashes": {
    "main.js": "84f7f8620e4ccde480b3a929483f51a0d051c2fe89443ecd4409faea663e071b"
  }
}

Fields #

FieldTypeRule
formatVersionnumber1 or 2
apiVersionnumber1
idtext[a-z][a-z0-9.-]{2,63}, stable across versions
versiontextMAJOR.MINOR.PATCH, for example 1.0.0
authortextrequired
entrytexta .js file inside the package, up to 128 KiB
nameobjectpt-BR and en required
descriptionobjectpt-BR and en required
permissionslistknown capabilities, no duplicates
targetslistdestinations for cat.http.send, up to 100
externalHostslistdestinations for cat.external.call, up to 100
settingsobjectinitial values read by cat.settings.get
settingsSchemaobjectoptional, up to 32 fields
hashesobjectSHA-256 of every file except the manifest

Permissions #

CapabilityUnlocks
traffic.readcat.events.on and HTTP content in menus
traffic.modifycat.proxy.onRequest and cat.proxy.onResponse
http.sendcat.http.send and cat.http.cancel
external.callcat.external.call
ui.menucat.ui.menu.register
ui.tabcat.ui.tab.register and cat.ui.update
storagecat.storage
findingscat.findings.add
repeatercat.tools.repeater.open
commandscat.commands.register and cat.commands.execute
pipeline.stepcat.pipeline.registerStep
parserscat.parsers.register
connector.runcat.connectors inside approved workflows

Destinations #

targets and externalHosts accept IDNA domains, decimal IPv4, bracketed IPv6 and explicit ports, with optional scheme and path.

ExampleReach
api.example.testexact domain, HTTP or HTTPS, any port
https://api.example.testHTTPS only on port 443
https://api.example.test:8443HTTPS only on port 8443
https://api.example.test/v1HTTPS only under /v1
*.example.testsubdomains of example.test, excluding the domain itself

Credentials in the URL, ?, #, %, spaces, global wildcards, wildcards on IPs, paths with .. and encoded slashes are rejected. Paths require a scheme. Private networks and loopback need explicit scope, and DNS and redirects are revalidated: a public domain cannot suddenly point to a private address.

Hashes #

Every package file except the manifest needs an entry in hashes with the lowercase hexadecimal SHA-256 of its bytes. The number of hashes must match the number of files. The web IDE computes everything automatically on export, and in CatSuite Studio the CatSuite: Update manifest hashes command does the same in VS Code.

Settings with settingsSchema #

JSON
{
  "settingsSchema": {
    "laboratory": {"title": {"pt-BR": "Modo laboratório", "en": "Laboratory mode"}, "type": "boolean"},
    "limit": {"title": {"pt-BR": "Limite", "en": "Limit"}, "type": "integer", "minimum": 1, "maximum": 50},
    "key": {"title": {"pt-BR": "Credencial", "en": "Credential"}, "type": "credential"}
  }
}

Accepted types: string, boolean, integer, number and credential. The secret alias means a credential reference, never its content. enum accepts 1 to 50 values and keys follow [a-zA-Z0-9_.-]{1,64}.

Format 2 #

formatVersion: 2 adds UUID revisionId and lineageId, parentHash, requiresSdk (from 1.0.0 to 1.4.0), an optional Ed25519 signature over canonical JSON and optional password protection. Editing in the app removes the old signature and creates a new revision; exporting signs with the local identity. See Security, vault and data protection.

Package limits #

ItemLimit
.catplug file10 MiB
Expanded content40 MiB
Files500
manifest.json64 KiB
Each file4 MiB
Pathsrelative, up to 200 characters, no leading /, \, : or ..

Symbolic links and duplicate files are rejected with E_PATH.