jshookmcp
MCPMCP server with 735 reverse-engineering and security analysis tools across 36 domains, including JavaScript deobfuscation, Frida, and network analysis.
git clone https://github.com/vmoranv/jshookmcpA search-first, profile-aware reverse-engineering workspace for AI agents.
Hook the page, capture the network, deobfuscate the bundle, disassemble the WASM, instrument the process — and let one MCP server keep the whole attack surface in reach without drowning the model in schemas.
Most MCP servers for JS analysis expose a handful of hand-rolled tools or wrap a single browser engine. jshook is closer to an operating system for front-end reverse engineering — 36 self-discovered domains, a search-first meta-tool that keeps token cost under control, and runtime recovery that survives broken pages and dropped sessions:
Search-first, profile-aware. The `search` profile loads about 3K tokens of tool metadata; the `full` profile exposes all 735 tools at around 109K tokens (measured 2026-10-10 — this figure scales with the tool count, so re-measure it when the catalog grows). Agents move between them as the task grows — `search` → `workflow` → `full` — instead of drowning in schemas from the first turn. Runtime recovery and session isolation. Streamable HTTP sessions restore activated domains, browser attach st…
- Source
- community
- Known advisories
- 0
- Maintenance
- active
- License
- none
- Age
- 0 months