Skills and Apps
What a permission prompt should tell you and usually does not
Extensions, skills and apps ask for access at the moment people are least able to assess it. The wording of that request is a security control.
Updated 6 min readqikfox
The short answer
A permission request should name what is being accessed, why it is needed for the thing the person just tried to do, what happens if they decline, and whether the access is one time or ongoing. Prompts that list capabilities in platform vocabulary get accepted without being read, which makes the consent meaningless.
Key points
- A request made at install time is answered by someone who wants the thing installed.
- Capability names are not explanations.
- Declining must remain a real option with a stated consequence.
- Ongoing access should be visible and revocable after the fact, not only at the prompt.
Why the current prompts do not work
The typical request appears during installation, before the person has used anything, and describes access in the platform's own terms: read and change data on all sites, access your files, run in the background. None of that connects to a task they were trying to accomplish.
The rational response, given no basis for judgement and a desire to proceed, is to accept. Repeated a few dozen times, that becomes a reflex, and the prompt has stopped functioning as a decision point.
The shape of a request people can judge
Ask at the moment the access is needed, for the narrowest thing that will do, in the words of the task.
- What: the specific data or capability, not the category.
- Why: tied to the action the person just took.
- Scope: this once, this site, or always.
- Consequence of declining: what stops working, honestly stated.
- Where to change it later, and how.
Permissions outlive the developer who asked for them
Extensions and skills change hands. A tool installed for one purpose can be sold, and the new owner inherits every permission granted to the old one. This has been the mechanism behind a long series of incidents, and it does not require anyone to be compromised.
Two things reduce it: keeping granted access narrow so an ownership change matters less, and periodically reviewing what is installed and what it can still reach. Platforms can help by surfacing transfers and by expiring access that has not been used.
Consent needs an afterwards
A single decision at install time is not consent to indefinite access. People need a place that lists what is installed, what each item can reach, when it last used that access, and a one step way to remove it.
That list is also the only practical way anyone notices the tool they stopped using two years ago still reads every page they visit.
Questions and answers
Related qikfox pages
App Store
Skills, apps, tools and agents.
Reviewing what you installed
A practical periodic check.
Agents need least privilege
The same principle for agents.
Security Center
Advisories and notices.
Back to The Perspective · Written and reviewed by the qikfox editorial team. Published .
Put the advice into practice
qikfox Safe Browser applies most of what this article describes by default, and works alongside qikfox Search, Antivirus and VPN.