Muse — Share with Captain
Overview
Share the page you're on with your Muse Captain. You choose what it reads — it never logs in, clicks or sends for you.
# Muse extension — Chrome Web Store submission & release (#1208) Everything needed to take the Muse extension from the developer zip to a Chrome Web Store install, in the order it happens. The code side is done in the repo; the steps marked **👤 owner** can only be done from AHigh Lab's Chrome Web Store developer account — Claude must not publish under anyone's identity. | | | |---|---| | Package | `node scripts/build-extension.mjs` → `dist/extension/muse-extension-<version>.zip` (+ `.sha256`), or the `muse-extension-<version>` artifact of the `extension` workflow | | Source | `voice-app/browser_extension/` (one codebase; the tenant zip serves it unpacked for developers) | | Connect page | `https://app.museai.ca/extension/connect` (SPA route, opened on install) | | Web CTA | `https://museai.ca/en/extension` · `https://museai.ca/fr/extension` | | Privacy policy | `https://museai.ca/en/privacy#browser-extension` (FR: `/fr/privacy#browser-extension`) | | Threat model | `docs/security/threat-model-browser-share.md` (S6 supply chain, S8 one-click pairing) | --- ## 1. 👤 Developer account (one time, ~15 min + verification delay) 1. Sign in with an **AHigh Lab** Google account that is not a personal one (e.g. a `dev@`/`extensions@` mailbox on the company domain) at <https://chrome.google.com/webstore/devconsole>. 2. Accept the developer agreement and pay the one-time **US$5** registration fee. 3. Turn on **2-Step Verification** on that Google account (required to publish). 4. **Account › Trader status**: declare **trader** (AHigh Lab inc. sells a service). The store then shows the business name, address, email and phone on the listing — use the company's public contact details. 5. Optional but recommended — **verified publisher**: verify `museai.ca` in Google Search Console with the same account, then link it under *Account › Publisher*. The listing then shows "museai.ca" as a verified publisher. 6. Note the **Publisher ID** (*Account* page) — needed only for automated releases (§6). ## 2. 👤 Reviewer account (one time) The extension does nothing useful without a Muse workspace, and a reviewer who cannot log in rejects the item ("functionality not working"). Create a dedicated workspace + owner login for review, e.g. `cws-review@museai.ca`, on a tenant with sharing on, then paste its credentials in *Item › Privacy › Test instructions* (text in §4.6). ## 3. 👤 Create the item (first version is manual) 1. Build the package on `main` (or download the workflow artifact) and check the sha256. 2. Dev console → **New item** → upload `muse-extension-<version>.zip`. 3. Fill *Store listing*, *Privacy* and *Distribution* with §4. 4. **Distribution › Visibility: Unlisted** (beta: only people with the link can install; it does not appear in search). Regions: all. 5. **Submit for review.** Typical review: 1–3 business days; longer the first time. 6. Once published, copy the listing URL (`https://chromewebstore.google.com/detail/<slug>/<item-id>`) and ship it (§5). ## 4. Listing content (copy-paste) ### 4.1 Store listing — English (default) - **Name** (from the manifest): Muse — Share with Captain - **Summary** (manifest, ≤132): Share the page you're on with your Muse Captain. You choose what it reads — it never logs in, clicks or sends for you. - **Category:** Productivity › Workflow & Planning - **Language:** English (add French below) - **Description:** > Muse is your AI teammate. This extension lets you show your Captain the page you're looking at — an Airbnb conversation, a listing, an invoice, a statement — in one click, from your own signed-in browser. > > HOW IT WORKS > 1. Add Muse to Chrome. Muse opens right after. > 2. Sign in to Muse (or confirm you're signed in) and click Connect. No code, no settings. > 3. On any page, click the Muse icon (or press Alt+Shift+M) → Share this page with Captain. Then ask your Captain about it. > > YOU CHOOSE WHAT IT READS > • It reads only the page you choose to share, when you click — its visible text, title and address. Never form fields, passwords, cookies or your browsing history. > • Sign-in, payment and banking pages are refused. > • It never logs in, never clicks Send and never buys anything for you. > • Optional, per site, switched on in Muse: it can fill in a reply you approved (you click Send), or read the pages you allowed during a 15-minute window you start. > • Disconnect any browser from Muse › Integrations, anytime. > > Requires a Muse workspace (museai.ca). Built in Québec. ### 4.2 Store listing — Français (Canada) - **Nom:** Muse — Partager avec Captain - **Résumé:** Partagez la page ouverte avec votre Captain Muse. Vous choisissez ce qu'il lit; il ne se connecte, ne clique et n'envoie rien. - **Description:** > Muse est votre coéquipier IA. Cette extension vous permet de montrer à votre Captain la page que vous consultez — une conversation Airbnb, une fiche, une facture, un relevé — en un clic, depuis votre propre navigateur déjà connecté. > > COMMENT ÇA MARCHE > 1. Ajoutez Muse à Chrome. Muse s'ouvre juste après. > 2. Connectez-vous à Muse (ou confirmez votre session) et cliquez sur Connecter. Aucun code, aucun réglage. > 3. Sur n'importe quelle page, cliquez l'icône Muse (ou Alt+Maj+M) → Partager cette page avec Captain. Posez-lui ensuite la question. > > VOUS CHOISISSEZ CE QU'IL LIT > • Il lit uniquement la page que vous choisissez de partager, quand vous cliquez — son texte visible, son titre et son adresse. Jamais les champs de formulaire, mots de passe, témoins ni votre historique. > • Les pages de connexion, de paiement et bancaires sont refusées. > • Il ne se connecte jamais, ne clique jamais sur Envoyer et n'achète rien à votre place. > • En option, par site, activé dans Muse : il peut remplir une réponse que vous avez approuvée (vous cliquez Envoyer), ou lire les pages autorisées pendant une fenêtre de 15 minutes que vous démarrez. > • Déconnectez n'importe quel navigateur depuis Muse › Intégrations, en tout temps. > > Nécessite un espace Muse (museai.ca). Conçu au Québec. ### 4.3 Graphics | Asset | Size | Source | |---|---|---| | Store icon | 128×128 | `voice-app/browser_extension/icons/icon-128.png` | | Screenshots (1–5) | 1280×800 | `docs/extension/store-assets/` (regenerate: §7) | | Small promo tile | 440×280 | `docs/extension/store-assets/promo-440x280.png` | ### 4.4 Privacy › Single purpose > Let the user share the web page they are viewing with their own Muse AI assistant, on their click, so the assistant can read it and help — and, only on sites the user enabled in Muse, fill in a reply the user approved or read pages the user allowed during a time window the user starts. ### 4.5 Privacy › Permission justifications | Permission | Justification (paste) | |---|---| | `activeTab` | Reads the visible text of the tab the user clicks the Muse button on (or uses the keyboard shortcut on), only at that moment. | | `scripting` | Injects the read-only text capture into that tab after the user's click, and — on sites the user enabled in Muse — fills a reply the user approved when they click Fill. | | `storage` | Keeps the connection to the user's Muse workspace (workspace address and a revocable device token), the last share shown in the popup, and pending approved replies. | | `alarms` | After the user fills an approved reply, checks periodically that the user sent it, so Muse can mark it done; stops when the reply expires. | | Host `https://*.museai.ca/*`, `https://*.ahighlab.cloud/*` | Muse's own domains: the user's workspace API the shares are sent to, and the Muse web app the extension connects from. No third-party site is a required host permission. | | Optional host `https://*.airbnb.ca/*`, `https://*.airbnb.com/*` | Requested only when the user enables Airbnb in Muse and clicks Fill or starts a read window, to fill an approved reply or read the Airbnb inbox pages the user allowed. | **Are you using remote code?** No. All JavaScript is in the package; the extension only fetches JSON data from the user's workspace. (`build-extension.mjs` refuses remote scripts, `eval` and inline scripts.) ### 4.6 Privacy › Data usage Collected (check): - **Website content** — text, title and address of pages the user explicitly shares. - **Web history** — the address and title of a page the user explicitly shares (declared conservatively; the extension never reads browsing history). Not collected: personally identifiable information, health, financial and payment information, authentication information (the extension never reads passwords or credentials; the device token is issued by Muse), personal communications, location, user activity (no clicks, keystrokes or scroll tracking). Certify all three: not sold to third parties; not used or transferred for purposes unrelated to the item's single purpose; not used or transferred to determine creditworthiness or for lending. **Privacy policy URL:** `https://museai.ca/en/privacy#browser-extension` **Test instructions** (paste, with the reviewer credentials from §2): > 1. Install the extension. A Muse tab opens at app.museai.ca/extension/connect. > 2. Sign in with: <reviewer email> / <reviewer password>. > 3. Click "Connect". The page shows "Captain connected — share a page whenever you like." > 4. Open any public web page (e.g. https://en.wikipedia.org/wiki/Montreal), click the Muse toolbar icon, then "Share this page with Captain". The popup shows "✓ Page shared with Captain". > 5. Back in Muse (app.museai.ca), ask: "What is the page I just shared about?" > Sign-in, payment and banking pages are refused by design. Fill and read features stay off unless enabled per site in Muse › Integrations; they are not needed to review the core function. ## 5. Make the listing the install path (one small PR once published) 1. `voice-app/browser_share.py`: set `CHROME_WEB_STORE_URL = "<listing URL>"`. (A single tenant can try a listing first with the env `BROWSER_EXTENSION_STORE_URL`.) Integrations then shows **Add Muse to Chrome** + **Connect this browser** instead of the zip and code. 2. `website`: pass the build arg `NEXT_PUBLIC_MUSE_EXTENSION_STORE_URL=<listing URL>` (Dockerfile default, or `deploy-portal.yml` build-args). `/extension` switches from "coming soon" to the store button. 3. Merge → the fleet, SPA shell and website deploy themselves. **Beta → public:** once installs on clean profiles and reconnects after a restart are confirmed with beta users, switch *Distribution › Visibility* to **Public** in the dashboard. Nothing in the code changes. ## 6. Releasing an update 1. Bump `version` in `voice-app/browser_extension/manifest.json` (the store refuses a version it has seen). Merge to `main`. 2. **Automated** (after one-time setup below): Actions → `extension` → *Run workflow* on `main`, `publish: true`. It rebuilds, checks the sha256, uploads, and submits for review. Users get the update automatically after approval. 3. **Manual:** dev console → item → *Package › Upload new package* → Submit. 4. If an `/api/browser/ext/*` contract changes incompatibly, raise `BROWSER_EXTENSION_MIN_VERSION` on the fleet **after** the new version is live: older builds then tell the owner to update (nothing is refused). ### Automated releases — 👤 one-time setup 1. Google Cloud console (AHigh Lab project) → enable **Chrome Web Store API**. 2. OAuth consent screen (internal or testing) → OAuth client of type *Desktop app*. 3. Get a refresh token for the scope `https://www.googleapis.com/auth/chromewebstore` while signed in as the developer account (OAuth Playground with your own client works). 4. GitHub → Settings → Environments → **`chrome-web-store`** (add required reviewers) → variables `CWS_PUBLISHER_ID`, `CWS_EXTENSION_ID`; secrets `CWS_CLIENT_ID`, `CWS_CLIENT_SECRET`, `CWS_REFRESH_TOKEN`. ## 7. Before each submission — checks - `node scripts/build-extension.mjs` passes (permissions, locales ≤ store limits, icons 16/32/48/128, no remote/inline code). - `cd voice-app-spa && npx vitest run src/extension/ src/lib/museExtension.test.ts src/views/ExtensionConnectView.test.ts` - Real-Chrome journey on a **blank profile**, including reconnect after a browser restart and a revoked device: `cd voice-app-spa/e2e && npx playwright test -c extension.config.ts` (loads the built package into a fresh Chromium profile against a local HTTPS mock of `*.museai.ca`; `STORE_SHOTS=1` also regenerates `docs/extension/store-assets/`). ## 8. Other browsers - **Edge:** the same zip installs from the Chrome Web Store (Edge asks to allow other stores). For a native listing, submit the same package at <https://partner.microsoft.com/dashboard/microsoftedge> (free). - **Brave, Arc, Opera, Vivaldi:** install from the Chrome Web Store listing as-is. - **Firefox / Safari / mobile:** not supported yet — the connect page and museai.ca/extension say so. ## 9. Common rejection reasons and where we stand | Store code | Meaning | Status | |---|---|---| | Purple Potassium | excessive/unused permissions | `tabs` removed; every permission justified in §4.5; build gate enforces the set | | Blue Argon | remote code | none; build gate | | Yellow Magnesium | functionality not working for the reviewer | reviewer account + test instructions (§2, §4.6) | | Purple Lithium / Red Titanium | privacy disclosure missing or mismatched | policy section `browser-extension` mirrors §4.6 and the threat model | | Yellow Zinc | metadata (name/summary/screenshots) | localized name/summary within limits; 1280×800 screenshots |
0 out of 5No ratings
Details
- Version1.0.0
- UpdatedSeptember 23, 2026
- Size38.74KiB
- Languages2 languages
- Developer
Email
captainahigh@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
Muse — Share with Captain has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
Muse — Share with Captain handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes