Jshookmcp – instrument your real signed-in Chrome via CDP Jshookmcp released an MCP server that instruments a real signed-in Chrome browser over CDP for front-end reverse engineering, exposing 735 tools across 36 self-discovered domains. The server's search profile loads about 3K tokens of tool metadata while the full profile exposes all 735 tools at roughly 109K tokens, measured 2026-10-10, with agents moving between search, workflow, and full profiles as tasks grow. It adds runtime recovery that restores activated domains, browser attach state, and coverage state after reconnects, plus per-client session isolation so two agents cannot trample each other's CDP sessions. A search-first, profile-aware reverse-engineering workspace for AI agents. Hook the page, capture the network, deobfuscate the bundle, disassemble the WASM, instrument the process — and let one MCP server keep the whole attack surface in reach without drowning the model in schemas. English · 中文 https://github.com/vmoranv/jshookmcp/blob/master/README.zh.md What's different what-makes-jshook-different · Capabilities capability-overview · Use cases use-cases · Highlights highlights · Transport transport-and-deployment · Registry registry-snapshot · Architecture architecture · Build build-from-source Documentation https://vmoranv.github.io/jshookmcp/ · Getting Started https://vmoranv.github.io/jshookmcp/guide/getting-started.html · Configuration https://vmoranv.github.io/jshookmcp/guide/configuration.html · Tool Reference https://vmoranv.github.io/jshookmcp/reference/ Sponsored by Swiftproxy https://www.swiftproxy.net/?code=R6KSMPQZ5 — Premium Residential Proxies for Web Automation · 10% off code: PROXY90 Most MCP servers for JS analysis expose a handful of hand-rolled tools or wrap a single browser engine. jshook is closer to an operating system for front-end reverse engineering — 36 self-discovered domains, a search-first meta-tool that keeps token cost under control, and runtime recovery that survives broken pages and dropped sessions: - Search-first, profile-aware. The search profile loads about 3K tokens of tool metadata; the full profile exposes all 735 tools at around 109K tokens measured 2026-10-10 — this figure scales with the tool count, so re-measure it when the catalog grows . Agents move between them as the task grows — search → workflow → full — instead of drowning in schemas from the first turn. - Runtime recovery and session isolation. Streamable HTTP sessions restore activated domains, browser attach state, and coverage state after reconnects; per-client browser-side state stays isolated so two agents cannot trample each other's CDP sessions. - Full-stack browser automation. Chromium and Camoufox via CDP with anti-detection, an explicit-input CAPTCHA solver no built-in page/feature probing , a self-signed HTTPS interception CA on demand, and HTTP/2 frame building. - Real reverse engineering, not string searches. WASM disassembly via wabt wasm2wat / wasm-decompile / wasm-objdump , Frida/Ghidra/IDA bridges, native FFI scanning, hardware breakpoints, PE introspection, GraphQL/Burp Suite proxy bridges, and AST transforms — not a single regex call wrapped as a tool. - Dynamic extensibility. Hot-reload plugins, declarative workflows, and auto-discovery keep the server growing without a redeploy. A scan of what's in the box. Each row links to the detailed Capability overview capability-overview below. | Area | Highlights | |---|---| | Tool profiles | search ~3K tokens, BM25 + hybrid vector ranking · workflow composite scripts · full all 735 tools | | Browser automation | Chromium and Camoufox · CDP attach to existing targets · anti-detection presets · explicit-input CAPTCHA solver · popup, download, permission, and protocol interceptors | | Network interception | HTTP/1.1 + HTTP/2 frame building · MITM proxy with auto-generated CA · WebSocket capture · GraphQL introspection helpers · Burp Suite bridge | | JS hooks and analysis | LLM-powered deobfuscation · crypto routine detection · AST comprehension · source-map reconstruction · script/scriptlet extraction and replay | | WASM reverse engineering | wabt disassembly / C transpilation wasm2wat / wasm-decompile / wasm-objdump / wasm2c · Binaryen wasm-opt · pure-TS section parser · import/export listing · section-grouped string extraction with name-section recovery · function-level binary diff · obfuscation detection · function- and basic-block-level instrumentation | | Process and memory forensics | Native FFI scanning · cross-reference graphs · hardware breakpoints · PE introspection · live process attach · memory read/write with region guards | | Binary instrumentation | Frida bridge · Ghidra and IDA bridges · syscall hooking · TLS keylog and session tooling · Mojo IPC analysis | | Android and APK analysis | APK static triage · manifest dump and query · apktool decode / build · jadx decompilation and code search · DEX scanning · native library listing · APK signing · unidbg emulation · runtime DEX dump | | Native runtime | Native emulator for foreign-architecture samples · platform introspection · Mojo IPC · Dart Inspector · ADB bridge for on-device traffic | | Encoding and transform | URL/Base64/Hex/JWT/Protobuf encoders · AST transforms · streaming decode pipelines | | Coordination | Background task queue with progress, cancellation, and async modes · multi-agent coordination · coverage reports | | Schema-first meta tools | describe tool · call tool with argument validation · coverage report · search tools | | Pluggable extension registry | Hot-reload plugins · declarative workflows · auto-discovered domains | | Scenario | What you do | Domains involved | |---|---|---| | Skim a minified bundle | search tools → deobfuscate → search in scripts → understand code | core | | Reverse a CAPTCHA challenge | Drive a Camoufox page → screenshot → solve with explicit input → replay | browser , canvas | | Capture and replay an OAuth flow | proxy start auto CA → network get requests → graphql introspect → graphql replay | proxy , network , graphql | | Reverse a WASM crypto routine | wasm dump → wasm disassemble → generate hooks → memory breakpoint | wasm , binary-instrument , memory | | Triage a suspicious APK | apk static triage → apk manifest dump → jadx decompile → dex scan file | binary-instrument | | Recover a dropped browser session | Reconnect Streamable HTTP → restore activated domains and browser state | browser , coordination | | Audit a Node process for credentials | process list → memory scan filtered → binary strings extract | process , memory , binary-instrument | | Build a custom workflow | list extension workflows → run extension workflow | workflow , extension-registry | | Hook a function in a live process | frida spawn → frida attach interceptor → frida run script → frida enumerate functions | binary-instrument | No global install needed — add to your MCP client config and you're ready. Claude Desktop / Cursor claude desktop config.json : { "mcpServers": { "jshook": { "command": "npx", "args": "-y", "@jshookmcp/jshook@latest" , "env": { "MCP TOOL PROFILE": "search", "npm config omit": "optional" } } } } Windows: use npx.cmd absolute path if npx is not found. This lightweight configuration skips optional ONNX, Z3, Binaryen, Camoufox, and Playwright packages. Remove npm config omit when those full-profile runtimes are required. The default stdio configuration starts one full jshook process per MCP host. To share the embedding model, browser runtime, and caches, start one local Streamable HTTP daemon: pnpm build pnpm daemon Vector search defaults to off for per-client stdio processes and on lazy-loaded for the shared HTTP daemon. Set SEARCH VECTOR ENABLED=false when lexical search is sufficient. Then point every MCP client at http://127.0.0.1:3000/mcp using its HTTP/URL server configuration. Each client receives its own MCP session and response route while heavyweight runtime resources remain in one process. Keep the default loopback bind; set MCP AUTH TOKEN before exposing the endpoint beyond localhost. { "env": { "MCP TOOL PROFILE": "search" // start here, ~3K tokens of metadata } } Switch MCP TOOL PROFILE to workflow once you start chaining composite scripts, or to full when you need every tool. coverage report shows the active set on demand. - Profile ladder. Start in search ~3K tokens of metadata ; promote to workflow when chaining composite scripts; escalate to full only when every tool is actually needed. coverage report shows what's active on demand. - Meta tools. describe tool returns the JSON Schema; call tool validates arguments before invocation; every tool ships with readOnlyHint / destructiveHint / idempotentHint / openWorldHint . - Browser automation. Chromium and Camoufox via CDP, attach to existing targets, anti-detection presets, popup/download/permission interceptors, explicit-input CAPTCHA solver, JS/CSS injection at three document phases, persisted coverage across reconnects. - Network interception. Auto-generated HTTPS interception CA, HTTP/1.1 + HTTP/2 frame building, WebSocket capture, GraphQL helpers, Burp Suite bridge — all on the same MCP tool surface. - Reverse engineering. wabt WASM disassembly wasm2wat / wasm-decompile / wasm-objdump and Binaryen wasm-opt , Frida/Ghidra/IDA bridges, hardware breakpoints, native FFI scanning, PE introspection, syscall hooking, AST transforms, source-map reconstruction. - Session recovery. Streamable HTTP transport restores activated domains, browser attach state, and coverage state after reconnects; browser-side state is isolated per client. - Plugins and workflows. Drop a directory, get a domain. Write a YAML pipeline, run it as one tool. The registry self-discovers. The server supports two transports out of the box. | Transport | When to use | Notes | |---|---|---| | stdio | Default for Claude Desktop, Cursor, and other single-host clients | One full process per MCP host; lightweight profile recommended | | Streamable HTTP | Multiple agents sharing the embedding model, browser runtime, and caches | Loopback bind by default; set MCP AUTH TOKEN before exposing externally | Both transports expose the same tool surface. coverage report shows which domains are activated in each session — long-running sessions restore browser attach state, coverage state, and tool activations across reconnects. For production deployments see the Security and Production guide https://vmoranv.github.io/jshookmcp/operations/security-and-production.html . - HTTP transport now multiplexes independent MCP sessions and restores runtime state after reconnects. - proxy start auto-generates a local HTTPS interception CA when needed. - Browser CAPTCHA solving is now explicit-input driven: pass taskKind , siteKey , imageBase64 , callbackName , and responseSelector as needed. Built-in widget/page signature probing is intentionally not used. The built-in surface below is generated from the runtime registry and checked in CI. - Package version: 0.4.2 - Built-in tools: 735 - Domains: adb-bridge , binary-instrument , browser , canvas , coordination , core , cross-domain , dart-inspector , debugger , encoding , exploit-dev , extension-registry , graphql , instrumentation , maintenance , memory , mojo-ipc , native-bridge , native-emulator , network , platform , process , protocol-analysis , proxy , session , sourcemap , streaming , syscall-hook , tasks , tls-inspector , trace , transform , v8-inspector , wasm , webgpu , workflow - Note: this snapshot is generated from the runtime registry; do not edit the counts by hand. - Runtime registry — domains auto-discovered via manifest.ts ; add a domain by creating one file. - Lazy initialization — handlers instantiated on first call, not at startup. - BM25 + vector search — search tools meta-tool with hybrid ranking and adaptive weights. - MCP ToolAnnotations — every tool carries readOnlyHint / destructiveHint / idempotentHint / openWorldHint . - Profile ladder — search ~3K tokens → workflow composite scripts → full all 735 tools . - Transport symmetry — stdio and Streamable HTTP expose the same surface; sessions are isolated per client. See the Architecture guide https://vmoranv.github.io/jshookmcp/guide/best-practices.html and Configuration reference https://vmoranv.github.io/jshookmcp/guide/configuration.html for the canonical details. Requirements: Node.js 22.22.2+, pnpm 10.x. pnpm install pnpm build pnpm start run the built server from dist/ pnpm dev run from source under tsx watch pnpm check drift guards metadata + openapi + domain + event contracts + lint + format check + typecheck + unit tests pnpm test Vitest unit suites pnpm test:e2e end-to-end browser/tooling suites pnpm daemon run the Streamable HTTP daemon after build Native helpers are bundled via pnpm build ; on first run the server may download optional runtimes ONNX, Z3, Binaryen, Camoufox, Playwright depending on the profile.