Static agent forms claims
An LLM agent reads the deobfuscated extension source and produces specific, falsifiable claims about what the extension does - not a generic risk category, but a concrete hypothesis: this code path exfiltrates form data, this endpoint receives credentials, this payload is assembled at runtime.