jshookmcp
A search-first, profile-aware reverse-engineering workspace for AI agents — 735 tools across 36 domains in one MCP server.
Install / Use
claude mcp add vmoranv -- npx -y github:vmoranv/jshookmcpIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of jshookmcp
jshookmcp scores 94/100 on our quality scale, 303rd of 1,112 Security skills we index (top 28%).
Its MCP Server is 16 KB long, well organised into 15 sections with 4 code examples: a thorough specification that gives an agent plenty to work with.
With 2,033 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated today, so jshookmcp is actively maintained.
- It is released under AGPL-3.0, a copyleft license: you can use it, but modified versions you distribute must carry the same license.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-10. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
jshookmcp compared with similar skills
All 4 of these similar skills score higher than jshookmcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| jshookmcp (this skill)by vmoranv | 94 | 2.0k | today | MCP Server |
| Agent-Reachby Panniantong | 100 | 95.3k | 2d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.9k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 86.7k | today | MCP Server |
Frequently asked questions
- How do I install jshookmcp?
- Run
claude mcp add vmoranv -- npx -y github:vmoranv/jshookmcp. The install tabs above show the steps for each supported agent. - Which AI agents does jshookmcp work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is jshookmcp safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is AGPL-3.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is jshookmcp still maintained?
- The repository was last updated today, so jshookmcp is actively maintained.
Skill content
View source on GitHub@jshookmcp/jshook
A search-first, profile-aware reverse-engineering workspace for AI agents.
Hook the page, capture the network, deobfuscate the bundle, disassemble the WASM, instrument the process — and let one MCP server keep the whole attack surface in reach without drowning the model in schemas.
English · 中文
<p align="center"> <a href="https://github.com/vmoranv/jshookmcp/stargazers"> <img src="https://img.shields.io/github/stars/vmoranv/jshookmcp?style=for-the-badge" alt="Stars" /> </a> <a href="https://github.com/vmoranv/jshookmcp/network/members"> <img src="https://img.shields.io/github/forks/vmoranv/jshookmcp?style=for-the-badge" alt="Forks" /> </a> <a href="https://github.com/vmoranv/jshookmcp/releases"> <img src="https://img.shields.io/github/v/tag/vmoranv/jshookmcp?style=for-the-badge&sort=semver" alt="Latest Release" /> </a> <a href="LICENSE"> <img src="https://img.shields.io/badge/license-AGPLv3-red?style=for-the-badge" alt="License" /> </a> </p> <p align="center"> <!-- npm badge: re-add once @jshookmcp/jshook is published --> <a href="https://nodejs.org/"> <img src="https://img.shields.io/badge/node-22.22.2%2B-brightgreen?style=for-the-badge&logo=node.js" alt="Node.js 22.22.2+" /> </a> <a href="https://www.typescriptlang.org/"> <img src="https://img.shields.io/badge/TypeScript-strict-3178C6?style=for-the-badge&logo=typescript&logoColor=white" alt="TypeScript strict" /> </a> <a href="https://modelcontextprotocol.io/"> <img src="https://img.shields.io/badge/MCP-current-8A2BE2?style=for-the-badge" alt="MCP current" /> </a> </p> <p align="center"> <a href="#what-makes-jshook-different">What's different</a> · <a href="#capability-overview">Capabilities</a> · <a href="#use-cases">Use cases</a> · <a href="#highlights">Highlights</a> · <a href="#transport-and-deployment">Transport</a> · <a href="#registry-snapshot">Registry</a> · <a href="#architecture">Architecture</a> · <a href="#build-from-source">Build</a> </p> <p align="center"> <a href="https://vmoranv.github.io/jshookmcp/">Documentation</a> · <a href="https://vmoranv.github.io/jshookmcp/guide/getting-started.html">Getting Started</a> · <a href="https://vmoranv.github.io/jshookmcp/guide/configuration.html">Configuration</a> · <a href="https://vmoranv.github.io/jshookmcp/reference/">Tool Reference</a> </p> <p align="center"> <a href="https://www.swiftproxy.net/?code=R6KSMPQZ5"> <img src="docs/public/swiftproxy_sponsor.png" alt="Sponsored by Swiftproxy" width="640" /> </a> </p> <p align="center"> <a href="https://www.swiftproxy.net/?code=R6KSMPQZ5"> <b>Sponsored by Swiftproxy</b> </a> — Premium Residential Proxies for Web Automation · 10% off code: <code>PROXY90</code> </p></div>
What makes jshook different
Most MCP servers for JS analysis expose a handful of hand-rolled tools or wrap a single browser engine. jshook is closer to an operating system for front-end reverse engineering — 36 self-discovered domains, a search-first meta-tool that keeps token cost under control, and runtime recovery that survives broken pages and dropped sessions:
- Search-first, profile-aware. The
searchprofile loads about 3K tokens of tool metadata; thefullprofile exposes all 735 tools at around 109K tokens (measured 2026-10-10 — this figure scales with the tool count, so re-measure it when the catalog grows). Agents move between them as the task grows —search→workflow→full— instead of drowning in schemas from the first turn. - Runtime recovery and session isolation. Streamable HTTP sessions restore activated domains, browser attach state, and coverage state after reconnects; per-client browser-side state stays isolated so two agents cannot trample each other's CDP sessions.
- Full-stack browser automation. Chromium and Camoufox via CDP with anti-detection, an explicit-input CAPTCHA solver (no built-in page/feature probing), a self-signed HTTPS interception CA on demand, and HTTP/2 frame building.
- Real reverse engineering, not string searches. WASM disassembly via wabt (
wasm2wat/wasm-decompile/wasm-objdump), Frida/Ghidra/IDA bridges, native FFI scanning, hardware breakpoints, PE introspection, GraphQL/Burp Suite proxy bridges, and AST transforms — not a single regex call wrapped as a tool. - Dynamic extensibility. Hot-reload plugins, declarative workflows, and auto-discovery keep the server growing without a redeploy.
Capability overview
A scan of what's in the box. Each row links to the detailed Capability overview below.
| Area | Highlights |
| --- | --- |
| Tool profiles | search (~3K tokens, BM25 + hybrid vector ranking) · workflow (composite scripts) · full (all 735 tools) |
| Browser automation | Chromium and Camoufox · CDP attach to existing targets · anti-detection presets · explicit-input CAPTCHA solver · popup, download, permission, and protocol interceptors |
| Network interception | HTTP/1.1 + HTTP/2 frame building · MITM proxy with auto-generated CA · WebSocket capture · GraphQL introspection helpers · Burp Suite bridge |
| JS hooks and analysis | LLM-powered deobfuscation · crypto routine detection · AST comprehension · source-map reconstruction · script/scriptlet extraction and replay |
| WASM reverse engineering | wabt disassembly / C transpilation (wasm2wat / wasm-decompile / wasm-objdump / wasm2c) · Binaryen wasm-opt · pure-TS section parser · import/export listing · section-grouped string extraction with name-section recovery · function-level binary diff · obfuscation detection · function- and basic-block-level instrumentation |
| Process and memory forensics | Native FFI scanning · cross-reference graphs · hardware breakpoints · PE introspection · live process attach · memory read/write with region guards |
| Binary instrumentation | Frida bridge · Ghidra and IDA bridges · syscall hooking · TLS keylog and session tooling · Mojo IPC analysis |
| Android and APK analysis | APK static triage · manifest dump and query · apktool decode / build · jadx decompilation and code search · DEX scanning · native library listing · APK signing · unidbg emulation · runtime DEX dump |
| Native runtime | Native emulator for foreign-architecture samples · platform introspection · Mojo IPC · Dart Inspector · ADB bridge for on-device traffic |
| Encoding and transform | URL/Base64/Hex/JWT/Protobuf encoders · AST transforms · streaming decode pipelines |
| Coordination | Background task queue with progress, cancellation, and async modes · multi-agent coordination · coverage reports |
| Schema-first meta tools | describe_tool · call_tool with argument validation · coverage_report · search_tools |
| Pluggable extension registry | Hot-reload plugins · declarative workflows · auto-discovered domains |
Use cases
| Scenario | What you do | Domains involved |
| --- | --- | --- |
| Skim a minified bundle | search_tools → deobfuscate → search_in_scripts → understand_code | core |
| Reverse a CAPTCHA challenge | Drive a Camoufox page → screenshot → solve with explicit input → replay | browser, canvas |
| Capture and replay an OAuth flow | proxy_start (auto CA) → network_get_requests → graphql_introspect → graphql_replay | proxy, network, graphql |
| Reverse a WASM crypto routine | wasm_dump → wasm_disassemble → generate_hooks → memory_breakpoint | wasm, binary-instrument, memory |
| Triage a suspicious APK | apk_static_triage → apk_manifest_dump → jadx_decompile → dex_scan_file | binary-instrument |
| Recover a dropped browser session | Reconnect Streamable HTTP → restore activated domains and browser state | browser, coordination |
| Audit a Node process for credentials | process_list → memory_scan_filtered → binary_strings_extract | process, memory, binary-instrument |
| Build a custom workflow | list_extension_workflows → run_extension_workflow | workflow, extension-registry |
| Hook a function in a live process | frida_spawn → frida_attach_interceptor → frida_run_script → frida_enumerate_functions | binary-instrument |
Quick start
No global install needed — add to your MCP client config and you're ready.
Claude Desktop / Cursor (claude_desktop_config.json):
{
"mcpServers": {
"jshook": {
"command": "npx",
"args": ["-y", "@jshookmcp/jshook@latest"],
"env": {
"MCP_TOOL_PROFILE": "search",
"npm_config_omit": "optional"
}
}
}
}
(Windows: use npx.cmd absolute path if npx is not found.)
This lightweight configuration skips optional ONNX, Z3, Binaryen, Camoufox, and Playwright
packages. Remove npm_config_omit when those full-profile runtimes are required.
Share one daemon across multiple agents
The default stdio configuration starts one full jshook process per MCP host. To share the embedding model, browser runtime, and caches, start one local Streamable HTTP daemon:
pnpm build
pnpm daemon
Vector search defaults to off for per-client stdio processes and on (lazy-loaded) for the shared
HTTP daemon. Set SEARCH_VECTOR_ENABLED=false when lexical search is sufficient.
Then point every MCP client at http://127.0.0.1:3000/mcp using its HTTP/URL server
configuration. Each client receives its own MCP session and response route while heavyweight
runtime resources remain in one process. Keep the default loopback bind; set MCP_AUTH_TOKEN
before exposing the endpoint beyond localhost.
Promote a profile as the task grows
{
"env": {
"MCP_TOOL_PROFILE": "search" // start here, ~3K tokens of metadata
}
}
Switch MCP_TOOL_PROFILE to workflow once you start chaining composite scripts, or to full
when you need every tool. coverage_report shows the active set on demand.
Highlights
- Profile ladder. Start in
search(~3K tokens of metadata); promote toworkflowwhen chaining composite scripts; escalate tofullonly when every tool is actually needed.coverage_reportshows what's active on demand. - Meta tools.
describe_toolreturns the JSON Schema;call_toolvalidates arguments before invocation; every tool ships withreadOnlyHint/destructiveHint/idempotentHint/openWorldHint. - Browser automation. Chromium and Camoufox via CDP, attach to existing targets, anti-detection presets, popup/download/permission interceptors, explicit-input CAPTCHA solver, JS/CSS injection at three document phases, persisted coverage across reconnects.
- Network interception. Auto-generated HTTPS interception CA, HTTP/1.1 + HTTP/2 frame building, WebSocket capture, GraphQL helpers, Burp Suite bridge — all on the same MCP tool surface.
- Reverse engineering. wabt WASM disassembly (
wasm2wat/wasm-decompile/wasm-objdump) and Binaryenwasm-opt, Frida/Ghidra/IDA bridges, hardware breakpoints, native FFI scanning, PE introspection, syscall hooking, AST transforms, source-map reconstruction. - Session recovery. Streamable HTTP transport restores activated domains, browser attach state, and coverage state after reconnects; browser-side state is isolated per client.
- Plugins and workflows. Drop a
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
95.3kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.9kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
86.7k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
