Skip to main content
Glama
jus1-c

Forensics Utils MCP Server

by jus1-c

chromium_decrypt_cookies_tool

Decrypt Chromium cookies from browser profiles using DPAPI or offline master key for forensic analysis.

Instructions

Attempt to decrypt Chromium cookies from a browser profile. Typical profile path: "C:\Users<user>\AppData\Local\Google\Chrome\User Data\Default".

Supports two modes:

  • Windows current-user context using Local State + DPAPI

  • Offline decryption when a decrypted Chromium master key is supplied via master_key_b64

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNoOptional exact cookie name filter
limitNoMaximum number of cookie records to return
host_keyNoOptional exact cookie domain filter
profile_pathYesAbsolute path to the Chromium profile directory
master_key_b64NoOptional decrypted Chromium master key in base64 form
local_state_pathNoOptional path to the Chromium `Local State` file

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations were provided, so the description carries the burden. It honestly says 'Attempt', indicating potential failure, and discloses the Windows/DPAPI constraint and offline mode. It does not explicitly state the operation is read-only, but the nature of decryption implies non-mutating behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and well-structured, with three tight blocks: core purpose, typical path, and supported modes. No filler or redundant content; every sentence contributes useful information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (DPAPI, encryption), the description covers the essential modes and a typical path. Output schema exists, so the lack of return-value explanation is acceptable. Missing details like error conditions or required permissions are minor given the concise scope.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so baseline is 3. The description adds value by explaining the purpose of master_key_b64 for offline decryption and mentioning 'Local State' + DPAPI, which enriches understanding beyond the raw schema field names.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states 'Attempt to decrypt Chromium cookies from a browser profile', using a specific verb and resource. It distinguishes from sibling parse tools (e.g., chromium_parse_cookies_tool) by emphasizing decryption, and provides a typical profile path as concrete context.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly outlines two usage modes (Windows current-user via DPAPI, and offline with master_key_b64), giving clear situational guidance. It does not explicitly exclude use of parse tools, but the decryption focus implies when this tool is appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/jus1-c/forensics-utils-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server