{"slug": "jshookmcp-instrument-your-real-signed-in-chrome-via-cdp", "title": "Jshookmcp – instrument your real signed-in Chrome via CDP", "summary": "Jshookmcp released an MCP server that instruments a real signed-in Chrome browser over CDP for front-end reverse engineering, exposing 735 tools across 36 self-discovered domains. The server's search profile loads about 3K tokens of tool metadata while the full profile exposes all 735 tools at roughly 109K tokens, measured 2026-10-10, with agents moving between search, workflow, and full profiles as tasks grow. It adds runtime recovery that restores activated domains, browser attach state, and coverage state after reconnects, plus per-client session isolation so two agents cannot trample each other's CDP sessions.", "body_md": "**A search-first, profile-aware reverse-engineering workspace for AI agents.**\n\n**Hook the page, capture the network, deobfuscate the bundle, disassemble the WASM, instrument the process — and let one MCP server keep the whole attack surface in reach without drowning the model in schemas.**\n\nEnglish · [中文](https://github.com/vmoranv/jshookmcp/blob/master/README.zh.md)\n\n[What's different](#what-makes-jshook-different) ·\n  [Capabilities](#capability-overview) ·\n  [Use cases](#use-cases) ·\n  [Highlights](#highlights) ·\n  [Transport](#transport-and-deployment) ·\n  [Registry](#registry-snapshot) ·\n  [Architecture](#architecture) ·\n  [Build](#build-from-source)\n\n[Documentation](https://vmoranv.github.io/jshookmcp/) ·\n  [Getting Started](https://vmoranv.github.io/jshookmcp/guide/getting-started.html) ·\n  [Configuration](https://vmoranv.github.io/jshookmcp/guide/configuration.html) ·\n  [Tool Reference](https://vmoranv.github.io/jshookmcp/reference/)\n\n[**Sponsored by Swiftproxy**](https://www.swiftproxy.net/?code=R6KSMPQZ5)\n — Premium Residential Proxies for Web Automation · 10% off code: `PROXY90`\n\nMost MCP servers for JS analysis expose a handful of hand-rolled tools or wrap a single browser engine. jshook is closer to an **operating system for front-end reverse engineering** — 36 self-discovered domains, a search-first meta-tool that keeps token cost under control, and runtime recovery that survives broken pages and dropped sessions:\n\n- **Search-first, profile-aware.** The`search` profile loads about 3K tokens of tool metadata; the`full` profile exposes all 735 tools at around 109K tokens (measured 2026-10-10 — this figure scales with the tool count, so re-measure it when the catalog grows). Agents move between them as the task grows —`search` →`workflow` →`full` — instead of drowning in schemas from the first turn.\n- **Runtime recovery and session isolation.** Streamable HTTP sessions restore activated domains, browser attach state, and coverage state after reconnects; per-client browser-side state stays isolated so two agents cannot trample each other's CDP sessions.\n- **Full-stack browser automation.** Chromium and Camoufox via CDP with anti-detection, an explicit-input CAPTCHA solver (no built-in page/feature probing), a self-signed HTTPS interception CA on demand, and HTTP/2 frame building.\n- **Real reverse engineering, not string searches.** WASM disassembly via wabt (`wasm2wat` /`wasm-decompile` /`wasm-objdump` ), Frida/Ghidra/IDA bridges, native FFI scanning, hardware breakpoints, PE introspection, GraphQL/Burp Suite proxy bridges, and AST transforms — not a single regex call wrapped as a tool.\n- **Dynamic extensibility.** Hot-reload plugins, declarative workflows, and auto-discovery keep the server growing without a redeploy.\n\nA scan of what's in the box. Each row links to the detailed [Capability overview](#capability-overview) below.\n\n| Area | Highlights | \n|---|---|\n| **Tool profiles** | `search` (~3K tokens, BM25 + hybrid vector ranking) ·`workflow` (composite scripts) ·`full` (all 735 tools) | \n| **Browser automation** | Chromium and Camoufox · CDP attach to existing targets · anti-detection presets · explicit-input CAPTCHA solver · popup, download, permission, and protocol interceptors | \n| **Network interception** | HTTP/1.1 + HTTP/2 frame building · MITM proxy with auto-generated CA · WebSocket capture · GraphQL introspection helpers · Burp Suite bridge | \n| **JS hooks and analysis** | LLM-powered deobfuscation · crypto routine detection · AST comprehension · source-map reconstruction · script/scriptlet extraction and replay | \n| **WASM reverse engineering** | wabt disassembly / C transpilation ( `wasm2wat` /`wasm-decompile` /`wasm-objdump` /`wasm2c` ) · Binaryen`wasm-opt` · pure-TS section parser · import/export listing · section-grouped string extraction with name-section recovery · function-level binary diff · obfuscation detection · function- and basic-block-level instrumentation | \n| **Process and memory forensics** | Native FFI scanning · cross-reference graphs · hardware breakpoints · PE introspection · live process attach · memory read/write with region guards | \n| **Binary instrumentation** | Frida bridge · Ghidra and IDA bridges · syscall hooking · TLS keylog and session tooling · Mojo IPC analysis | \n| **Android and APK analysis** | APK static triage · manifest dump and query · apktool decode / build · jadx decompilation and code search · DEX scanning · native library listing · APK signing · unidbg emulation · runtime DEX dump | \n| **Native runtime** | Native emulator for foreign-architecture samples · platform introspection · Mojo IPC · Dart Inspector · ADB bridge for on-device traffic | \n| **Encoding and transform** | URL/Base64/Hex/JWT/Protobuf encoders · AST transforms · streaming decode pipelines | \n| **Coordination** | Background task queue with progress, cancellation, and async modes · multi-agent coordination · coverage reports | \n| **Schema-first meta tools** | `describe_tool` ·`call_tool` with argument validation ·`coverage_report` ·`search_tools` | \n| **Pluggable extension registry** | Hot-reload plugins · declarative workflows · auto-discovered domains | \n\n| Scenario | What you do | Domains involved | \n|---|---|---|\n| Skim a minified bundle | `search_tools` →`deobfuscate` →`search_in_scripts` →`understand_code` | `core` | \n| Reverse a CAPTCHA challenge | Drive a Camoufox page → screenshot → solve with explicit input → replay | `browser` ,`canvas` | \n| Capture and replay an OAuth flow | `proxy_start` (auto CA) →`network_get_requests` →`graphql_introspect` →`graphql_replay` | `proxy` ,`network` ,`graphql` | \n| Reverse a WASM crypto routine | `wasm_dump` →`wasm_disassemble` →`generate_hooks` →`memory_breakpoint` | `wasm` ,`binary-instrument` ,`memory` | \n| Triage a suspicious APK | `apk_static_triage` →`apk_manifest_dump` →`jadx_decompile` →`dex_scan_file` | `binary-instrument` | \n| Recover a dropped browser session | Reconnect Streamable HTTP → restore activated domains and browser state | `browser` ,`coordination` | \n| Audit a Node process for credentials | `process_list` →`memory_scan_filtered` →`binary_strings_extract` | `process` ,`memory` ,`binary-instrument` | \n| Build a custom workflow | `list_extension_workflows` →`run_extension_workflow` | `workflow` ,`extension-registry` | \n| Hook a function in a live process | `frida_spawn` →`frida_attach_interceptor` →`frida_run_script` →`frida_enumerate_functions` | `binary-instrument` | \n\nNo global install needed — add to your MCP client config and you're ready.\n\n**Claude Desktop / Cursor (`claude_desktop_config.json`):**\n\n```\n{\n  \"mcpServers\": {\n    \"jshook\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@jshookmcp/jshook@latest\"],\n      \"env\": {\n        \"MCP_TOOL_PROFILE\": \"search\",\n        \"npm_config_omit\": \"optional\"\n      }\n    }\n  }\n}\n```\n\n*(Windows: use `npx.cmd` absolute path if `npx` is not found.)*\n\nThis lightweight configuration skips optional ONNX, Z3, Binaryen, Camoufox, and Playwright\npackages. Remove `npm_config_omit` when those full-profile runtimes are required.\n\nThe default stdio configuration starts one full jshook process per MCP host. To share the embedding model, browser runtime, and caches, start one local Streamable HTTP daemon:\n\n```\npnpm build\npnpm daemon\n```\n\nVector search defaults to off for per-client stdio processes and on (lazy-loaded) for the shared\nHTTP daemon. Set `SEARCH_VECTOR_ENABLED=false` when lexical search is sufficient.\n\nThen point every MCP client at `http://127.0.0.1:3000/mcp` using its HTTP/URL server\nconfiguration. Each client receives its own MCP session and response route while heavyweight\nruntime resources remain in one process. Keep the default loopback bind; set `MCP_AUTH_TOKEN`\nbefore exposing the endpoint beyond localhost.\n\n```\n{\n  \"env\": {\n    \"MCP_TOOL_PROFILE\": \"search\"     // start here, ~3K tokens of metadata\n  }\n}\n```\n\nSwitch `MCP_TOOL_PROFILE` to `workflow` once you start chaining composite scripts, or to `full`\nwhen you need every tool. `coverage_report` shows the active set on demand.\n\n- **Profile ladder.** Start in`search` (~3K tokens of metadata); promote to`workflow` when chaining composite scripts; escalate to`full` only when every tool is actually needed.`coverage_report` shows what's active on demand.\n- **Meta tools.**`describe_tool` returns the JSON Schema;`call_tool` validates arguments before invocation; every tool ships with`readOnlyHint` /`destructiveHint` /`idempotentHint` /`openWorldHint` .\n- **Browser automation.** Chromium and Camoufox via CDP, attach to existing targets, anti-detection presets, popup/download/permission interceptors, explicit-input CAPTCHA solver, JS/CSS injection at three document phases, persisted coverage across reconnects.\n- **Network interception.** Auto-generated HTTPS interception CA, HTTP/1.1 + HTTP/2 frame building, WebSocket capture, GraphQL helpers, Burp Suite bridge — all on the same MCP tool surface.\n- **Reverse engineering.** wabt WASM disassembly (`wasm2wat` /`wasm-decompile` /`wasm-objdump` ) and Binaryen`wasm-opt` , Frida/Ghidra/IDA bridges, hardware breakpoints, native FFI scanning, PE introspection, syscall hooking, AST transforms, source-map reconstruction.\n- **Session recovery.** Streamable HTTP transport restores activated domains, browser attach state, and coverage state after reconnects; browser-side state is isolated per client.\n- **Plugins and workflows.** Drop a directory, get a domain. Write a YAML pipeline, run it as one tool. The registry self-discovers.\n\nThe server supports two transports out of the box.\n\n| Transport | When to use | Notes | \n|---|---|---|\n| **stdio** | Default for Claude Desktop, Cursor, and other single-host clients | One full process per MCP host; lightweight profile recommended | \n| **Streamable HTTP** | Multiple agents sharing the embedding model, browser runtime, and caches | Loopback bind by default; set `MCP_AUTH_TOKEN` before exposing externally | \n\nBoth transports expose the same tool surface. `coverage_report` shows which domains are\nactivated in each session — long-running sessions restore browser attach state, coverage state,\nand tool activations across reconnects.\n\nFor production deployments see the [Security and Production guide](https://vmoranv.github.io/jshookmcp/operations/security-and-production.html).\n\n- HTTP transport now multiplexes independent MCP sessions and restores runtime state after reconnects.\n- `proxy_start` auto-generates a local HTTPS interception CA when needed.\n- Browser CAPTCHA solving is now explicit-input driven: pass `taskKind` ,`siteKey` ,`imageBase64` ,`callbackName` , and`responseSelector` as needed. Built-in widget/page signature probing is intentionally not used.\n\nThe built-in surface below is generated from the runtime registry and checked in CI.\n\n- Package version: `0.4.2`\n- Built-in tools: `735`\n- Domains: `adb-bridge` ,`binary-instrument` ,`browser` ,`canvas` ,`coordination` ,`core` ,`cross-domain` ,`dart-inspector` ,`debugger` ,`encoding` ,`exploit-dev` ,`extension-registry` ,`graphql` ,`instrumentation` ,`maintenance` ,`memory` ,`mojo-ipc` ,`native-bridge` ,`native-emulator` ,`network` ,`platform` ,`process` ,`protocol-analysis` ,`proxy` ,`session` ,`sourcemap` ,`streaming` ,`syscall-hook` ,`tasks` ,`tls-inspector` ,`trace` ,`transform` ,`v8-inspector` ,`wasm` ,`webgpu` ,`workflow`\n- Note: this snapshot is generated from the runtime registry; do not edit the counts by hand.\n\n- **Runtime registry** — domains auto-discovered via`manifest.ts` ; add a domain by creating one file.\n- **Lazy initialization** — handlers instantiated on first call, not at startup.\n- **BM25 + vector search** —`search_tools` meta-tool with hybrid ranking and adaptive weights.\n- **MCP `ToolAnnotations`** — every tool carries` readOnlyHint` /`destructiveHint` /`idempotentHint` /`openWorldHint` .\n- **Profile ladder** —`search` (~3K tokens) →`workflow` (composite scripts) →`full` (all 735 tools).\n- **Transport symmetry** — stdio and Streamable HTTP expose the same surface; sessions are isolated per client.\n\nSee the [Architecture guide](https://vmoranv.github.io/jshookmcp/guide/best-practices.html) and [Configuration reference](https://vmoranv.github.io/jshookmcp/guide/configuration.html) for the canonical details.\n\nRequirements: Node.js 22.22.2+, pnpm 10.x.\n\n```\npnpm install\npnpm build\npnpm start           # run the built server from dist/\npnpm dev             # run from source under tsx watch\npnpm check           # drift guards (metadata + openapi + domain + event contracts) + lint + format check + typecheck + unit tests\npnpm test            # Vitest unit suites\npnpm test:e2e        # end-to-end browser/tooling suites\npnpm daemon          # run the Streamable HTTP daemon after build\n```\n\nNative helpers are bundled via `pnpm build`; on first run the server may download optional\nruntimes (ONNX, Z3, Binaryen, Camoufox, Playwright) depending on the profile.", "url": "https://wpnews.pro/news/jshookmcp-instrument-your-real-signed-in-chrome-via-cdp", "canonical_source": "https://github.com/vmoranv/jshookmcp", "published_at": "2026-10-11 02:13:33+00:00", "updated_at": "2026-10-11 02:20:49.604795+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "developer-tools", "ai-tools", "ai-crawlers"], "entities": ["jshookmcp", "Chrome", "CDP", "Camoufox", "wabt", "Frida", "Ghidra", "Burp Suite"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/jshookmcp-instrument-your-real-signed-in-chrome-via-cdp", "markdown": "https://wpnews.pro/news/jshookmcp-instrument-your-real-signed-in-chrome-via-cdp.md", "text": "https://wpnews.pro/news/jshookmcp-instrument-your-real-signed-in-chrome-via-cdp.txt", "jsonld": "https://wpnews.pro/news/jshookmcp-instrument-your-real-signed-in-chrome-via-cdp.jsonld"}}