Assess a Thunderbird Extension Asking for Unrestricted Computer Access
An extension advertised as a small convenience can request substantially more access than its visible button suggests. When Thunderbird asks for unrestricted access to the application and computer, evaluate that scope before accepting the installation.
Mozilla explains that extensions using this permission can reach Thunderbird's internal interfaces without requesting each individual permission. Their capabilities may include changing messages, contacts, calendars and passwords, and reading, modifying or executing files on the computer.
This is broader than permission to list mail folders or modify a message being composed. The warning describes what the extension can do; it does not, by itself, establish that its developer is misusing that capability.
Compare the capability with the actual work
Write a one-sentence requirement before deciding: for example, insert an approved text block into a draft. Identify which information that job should require and why the proposed extension says it needs broader access.
Read the specific developer's explanation, release information and support history. Record the extension's exact identity and version so a similarly named download is not substituted during the decision. An unexplained permission should remain unresolved rather than becoming acceptable through repeated clicking.
For a shared business computer, include the other material accessible in that user session in the assessment. Restricting your mental scope to the currently selected inbox overlooks the computer access described by this particular warning.
Make the acceptance check match the decision
If the task can be completed with a built-in feature, compare that result before adding software. If the extension is required and approved, first exercise its promised function with harmless material in an appropriately isolated test environment.
Check that the function produces the expected draft or view and does not unexpectedly change the sample. A successful feature test still cannot prove that unrestricted code will only perform the visible action. Keep the permission decision and the functionality result as separate records.
Do not assume that narrowing website access, switching mail accounts, or leaving a sensitive folder unselected limits this permission. If the organisation cannot accept its stated reach, cancel the installation and seek a different way to perform the task. The useful outcome is a documented scope decision, not simply getting the warning to disappear.
Sources: Thunderbird documentation.