by vmoranv
A search-first, profile-aware reverse-engineering workspace for AI agents — 735 tools across 36 domains in one MCP server.
# Add to your Claude Code skills
git clone https://github.com/vmoranv/jshookmcpLast scanned: 10/11/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@devicefarmer/adbkit: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@graphql-tools/utils: GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@puppeteer/browsers: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "basic-ftp: basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)",
"severity": "high"
},
{
"type": "npm-audit",
"message": "extract-zip: extract-zip unvalidated symlink path traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "get-uri: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mockttp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "node-forge: node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements",
"severity": "high"
},
{
"type": "npm-audit",
"message": "pac-proxy-agent: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "proxy-agent: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "rebrowser-puppeteer-core: Vulnerability found",
"severity": "high"
}
],
"status": "WARNING",
"scannedAt": "2026-10-11T10:38:07.579Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how jshookmcp compares with popular alternatives.
jshookmcp is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by vmoranv. A search-first, profile-aware reverse-engineering workspace for AI agents — 735 tools across 36 domains in one MCP server. It has 2,035 GitHub stars.
jshookmcp returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/vmoranv/jshookmcp" and add it to your Claude Code skills directory (see the Installation section above).
jshookmcp is primarily written in TypeScript. It is open-source under vmoranv on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh jshookmcp against similar tools.
No comments yet. Be the first to share your thoughts!
Based on votes and bookmarks from developers who liked this skill
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A search-first, profile-aware reverse-engineering workspace for AI agents.
Hook the page, capture the network, deobfuscate the bundle, disassemble the WASM, instrument the process — and let one MCP server keep the whole attack surface in reach without drowning the model in schemas.
English · 中文
Most MCP servers for JS analysis expose a handful of hand-rolled tools or wrap a single browser engine. jshook is closer to an operating system for front-end reverse engineering — 36 self-discovered domains, a search-first meta-tool that keeps token cost under control, and runtime recovery that survives broken pages and dropped sessions:
search profile loads about 3K tokens of tool metadata; the full profile exposes all 735 tools at around 109K tokens (measured 2026-10-10 — this figure scales with the tool count, so re-measure it when the catalog grows). Agents move between them as the task grows — search → workflow → full — instead of drowning in schemas from the first turn.wasm2wat / wasm-decompile / wasm-objdump), Frida/Ghidra/IDA bridges, native FFI scanning, hardware breakpoints, PE introspection, GraphQL/Burp Suite proxy bridges, and AST transforms — not a single regex call wrapped as a tool.A scan of what's in the box. Each row links to the detailed Capability overview below.
| Area | Highlights |
|---|---|
| Tool profiles | search (~3K tokens, BM25 + hybrid vector ranking) · workflow (composite scripts) · full (all 735 tools) |
| Browser automation | Chromium and Camoufox · CDP attach to existing targets · anti-detection presets · explicit-input CAPTCHA solver · popup, download, permission, and protocol interceptors |
| Network interception | HTTP/1.1 + HTTP/2 frame building · MITM proxy with auto-generated CA · WebSocket capture · GraphQL introspection helpers · Burp Suite bridge |
| JS hooks and analysis | LLM-powered deobfuscation · crypto routine detection · AST comprehension · source-map reconstruction · script/scriptlet extraction and replay |
| WASM reverse engineering | wabt disassembly / C transpilation (wasm2wat / wasm-decompile / wasm-objdump / wasm2c) · Binaryen wasm-opt · pure-TS section parser · import/export listing · section-grouped string extraction with name-section recovery · function-level binary diff · obfuscation detection · function- and basic-block-level instrumentation |
| Process and memory forensics | Native FFI scanning · cross-reference graphs · hardware breakpoints · PE introspection · live process attach · memory read/write with region guards |
| Binary instrumentation | Frida bridge · Ghidra and IDA bridges · syscall hooking · TLS keylog and session tooling · Mojo IPC analysis |
| Android and APK analysis | APK static triage · manifest dump and query · apktool decode / build · jadx decompilation and code search · DEX scanning · native library listing · APK signing · unidbg emulation · runtime DEX dump |
| Native runtime | Native emulator for foreign-architecture samples · platform introspection · Mojo IPC · Dart Inspector · ADB bridge for on-device traffic |
| Encoding and transform | URL/Base64/Hex/JWT/Protobuf encoders · AST transforms · streaming decode pipelines |
| Coordination | Background task queue with progress, cancellation, and async modes · multi-agent coordination · coverage reports |
| Schema-first meta tools | describe_tool · call_tool with argument validation · coverage_report · search_tools |
| Pluggable extension registry | Hot-reload plugins · declarative workflows · auto-discovered domains |
| Scenario | What you do | Domains involved |
|---|---|---|
| Skim a minified bundle | search_tools → deobfuscate → search_in_scripts → understand_code |
core |
| Reverse a CAPTCHA challenge | Drive a Camoufox page → screenshot → solve with explicit input → replay | browser, canvas |
| Capture and replay an OAuth flow | proxy_start (auto CA) → network_get_requests → graphql_introspect → graphql_replay |
proxy, network, graphql |
| Reverse a WASM crypto routine | wasm_dump → wasm_disassemble → generate_hooks → memory_breakpoint |
wasm, binary-instrument, memory |
| Triage a suspicious APK | apk_static_triage → apk_manifest_dump → jadx_decompile → dex_scan_file |
binary-instrument |
| Recover a dropped browser session | Reconnect Streamable HTTP → restore activated domains and browser state | browser, coordination |
| Audit a Node process for credentials | process_list → memory_scan_filtered → binary_strings_extract |
process, memory, binary-instrument |
| Build a custom workflow | list_extension_workflows → run_extension_workflow |
workflow, extension-registry |
| Hook a function in a live process | frida_spawn → frida_attach_interceptor → frida_run_script → frida_enumerate_functions |
binary-instrument |
No global install needed — add to your MCP client config and you're ready.
Claude Desktop / Cursor (claude_desktop_config.json):
{
"mcpServers": {
"jshook": {
"command": "npx",
"args": ["-y", "@jshookmcp/jshook@latest"],
"env": {
"MCP_TOOL_PROFILE": "search",
"npm_config_omit": "optional"
}
}
}
}
(Windows: use npx.cmd absolute path if npx is not found.)
This lightweight configuration skips optional ONNX, Z3, Binaryen, Camoufox, and Playwright
packages. Remove npm_config_omit when those full-profile runtimes are required.
The default stdio configuration starts one full jshook process per MCP host. To share the embedding model, browser runtime, and caches, start one local Streamable HTTP daemon:
pnpm build
pnpm daemon
Vector search defaults to off for per-client stdio processes and on (lazy-loaded) for the shared
HTTP daemon. Set SEARCH_VECTOR_ENABLED=false when lexical search is sufficient.
Then point every MCP client at `h