Cobalt Scoping Assistant
A lightweight tool to record web application usage for penetration test scoping
As of June 2026, Cobalt Scoping Assistant has 29 users in the Workflow & Planning category.
Usersno change0%
29
29
Ratingno change0%
—
— reviews
Reviewsno change0%
—
Version
1.0.1
Manifest V3
90-day change · In the last 90 days this extension 1 version update.
History
7 snapshotsTracking since Apr 26, 2026.
View as table
| Date | Users | Rating | Reviews | Version |
|---|---|---|---|---|
| Apr 26, 2026 | — | — | — | 1.0.0 |
| May 9, 2026 | — | — | — | 1.0.0 |
| May 14, 2026 | 4 | — | — | 1.0.0 |
| May 20, 2026 | 9 | — | — | 1.0.0 |
| May 26, 2026 | 15 | — | — | 1.0.0 |
| Jun 3, 2026 | 28 | — | — | 1.0.0 |
| Jun 8, 2026 | 28 | — | — | 1.0.1 |
| Now | 29 | — | — | 1.0.1 |
Permissions & access
- Permissions
- webRequestwebNavigationtabsdownloadsscripting
- Host access
- <all_urls>
Screenshots
About
The Cobalt Scoping Assistant helps Cobalt customers quickly scope web application penetration tests by recording a live browsing session and automatically extracting the information needed to define test coverage. How it works: Start a recording, browse the target application as you normally would, then stop and export. The extension captures everything in the background without interrupting your workflow — and recording continues seamlessly across new tabs. What gets captured: - Unique dynamic pages visited (pages that issue mutating HTTP requests (POST, PUT, PATCH, DELETE)). - API endpoints and routes (detected from network requests). - All internal links found on the pages the user visits. - Technology stack fingerprints inferred from HTTP headers, cookies, and URL patterns (e.g. Rails, Django, WordPress, GraphQL, PHP, and many more). Domain filtering: Focus your recording on specific domains so third-party resources, CDNs, and analytics noise are excluded from your export. Built-in presets automatically filter out common static asset providers (Google APIs, Cloudflare, jsDelivr, etc.). Privacy-first: All data is processed and stored locally in your browser. Nothing is sent to any external server. The exported JSON file must be manually provided to Cobalt by you. Export format: Results are exported as a structured JSON file containing visited dynamic pages, discovered API routes, and inferred technologies — ready to feed directly into your scoping workflow.
Technical
- Version
- 1.0.1
- Manifest
- V3
- Size
- 149KiB
- Min Chrome
- 88
- Languages
- 1
- Featured
- No
Metadata
- ID
- oodkjfjfgjiojbfghmiipgjfhjlkiohb
- Developer ID
- ucece170980caadd0be0d0db73efaf915
- Developer Email
- [email protected]
- Created
- Apr 25, 2026
- Last Updated (Store)
- May 28, 2026
- Last Scraped
- Jun 8, 2026
- Website
- —
- Support URL
- —
- Privacy Policy
- https://www.cobalt.io/terms
Data sourced from the Chrome Web Store · last verified Jun 8, 2026.