JS Reverse MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DEBUG | No | Debug log settings (e.g., mcp:*). | |
| browserUrl | No | Command line argument to connect to a browser via URL (e.g., http://127.0.0.1:9222). | |
| wsEndpoint | No | Command line argument to connect to a browser via WebSocket endpoint. | |
| GEMINI_MODEL | No | The Gemini model to use (e.g., gemini-2.0-flash-exp). | gemini-2.0-flash-exp |
| OPENAI_MODEL | No | The OpenAI model to use (e.g., gpt-4o). | gpt-4o |
| GEMINI_API_KEY | No | API key for Gemini. | |
| OPENAI_API_KEY | No | API key for OpenAI. | |
| ANTHROPIC_MODEL | No | The Anthropic model to use (e.g., claude-3-5-sonnet-20241022). | claude-3-5-sonnet-20241022 |
| BROWSER_CHANNEL | No | The browser channel to use (e.g., chrome). | |
| GEMINI_CLI_PATH | No | Path to the Gemini CLI. | |
| BROWSER_HEADLESS | No | Whether to run the browser in headless mode (true/false). | true |
| BROWSER_ISOLATED | No | Whether to run the browser in isolated mode (true/false). | true |
| ANTHROPIC_API_KEY | No | API key for Anthropic. | |
| USE_STEALTH_SCRIPTS | No | Whether to use stealth scripts to avoid detection (true/false). | false |
| DEFAULT_LLM_PROVIDER | No | The AI provider to use. Valid values: openai, anthropic, or gemini. | |
| REMOTE_DEBUGGING_URL | No | The URL for remote debugging an existing Chrome instance. | http://localhost:9222 |
| REMOTE_DEBUGGING_PORT | No | The port for remote debugging. | 9222 |
| BROWSER_EXECUTABLE_PATH | No | The file path to the Chrome/Chromium executable. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| analyze_source_mapsB | Parse a source map and summarize original sources, embedded content coverage, and likely reverse targets. |
| auto_rebuild_fix_loopC | Create a resumable env-fix loop plan from runtime errors and observed capabilities. |
| collect_codeC | Collect JavaScript code from a page with smart modes (summary/priority/incremental/full). |
| create_reverse_task_from_requestB | Create a reverse task directly from one captured network request. |
| diagnose_environmentB | Run static environment diagnostics for startup, AI provider setup, and artifact output paths. |
| diff_session_stateA | Compare cookies, localStorage, and sessionStorage snapshots before and after a page action. |
| explain_reverse_stageA | Explain a reverse-engineering stage with goals, entry criteria, avoid list, and recommended tools. |
| export_diagnostic_bundleB | Export a compact support bundle with environment, AI runtime, browser, and setup diagnostics. |
| export_har_snapshotB | Export selected page network requests into a compact HAR-like snapshot for offline analysis. |
| export_rebuild_bundleB | Export a local Node rebuild bundle from observed reverse-engineering evidence. |
| generate_parameter_reportB | Generate a concise parameter-chain report from target, candidates, evidence, and next steps. |
| get_rebuild_health_reportA | Produce a compact rebuild health report for one reverse task, including env blockers, evidence aggregates, and next fixes. |
| get_referenceA | Read one packaged reference doc, or return its compact summary. |
| get_reference_routeB | Route by stage, topic, or natural-language query to the most relevant reference docs. |
| infer_websocket_schemaB | Infer JSON field types, message type distribution, and non-JSON counts from WebSocket messages. |
| list_pagesA | Get a list of pages open in the browser. |
| list_task_artifactsB | List files, sizes, and update times for a reverse task artifact directory. |
| locate_candidate_functionsB | Score likely signature/token/request functions from code files, params, headers, and target URL hints. |
| manage_reverse_taskC | Unified reverse task entry for list/get/summarize/progress/update/timeline/archive/restore/search/tag/prune/compare actions. Preferred task-management entry to reduce tool-selection overhead. |
| navigate_pageA | Navigates the currently selected page to a URL, or performs back/forward/reload navigation. Waits for DOMContentLoaded event (not full page load). Default timeout is 10 seconds. |
| network_requestB | List network requests, or get one request by reqid. |
| orchestrate_reverse_taskC | High-level reverse-task orchestrator that syncs task state, picks the primary next step, and returns a compact execution plan. |
| probe_runtime_capabilitiesC | Probe browser runtime capabilities and compare them with Node rebuild assumptions. |
| recommend_next_stepB | Recommend the next reverse-engineering action from lightweight workflow signals. |
| record_page_flowA | Persist a page interaction flow draft for later replay and evidence reuse. |
| record_reverse_evidenceC | Append structured reverse-engineering evidence to a task artifact log. |
| repair_browser_connectionA | Diagnose Chrome remote-debugging connectivity and return concrete repair commands. |
| replay_page_flowC | Replay recorded page flow actions through PageController. |
| run_reverse_agentC | One-shot reverse agent entry: repeatedly plans and executes the main reverse chain until blocked, stalled, or reaching the analysis checkpoint. |
| search_in_scriptsA | Search in collected script cache with regex pattern. |
| search_in_sourcesB | Searches for a string or regex pattern in all loaded JavaScript sources. Returns matching lines with script ID, URL, and line number. Use get_script_source with startLine/endLine to view full context around matches. |
| select_pageA | Select a page as a context for future tool calls. |
| start_reverse_taskB | Initialize a task artifact directory with task.json, state.json, report.md, and first timeline entry. |
| trace_request_to_codeC | Trace a captured network request to initiator stack frames and optional static code candidates. |
| understand_codeB | Analyze code structure/business/security with AI + static analysis. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/NoOne-hub/JSReverser-MCP'
If you have feedback or need assistance with the MCP directory API, please join our Discord server