Skip to main content
Glama

@jshookmcp/jshook

License: AGPLv3 Node.js 20.19+ or 22.12+ TypeScript MCP pnpm

English | 中文

这是一个 MCP (Model Context Protocol) 服务器,提供了一个由运行时注册表驱动的内置工具目录,用于 AI 辅助的 JavaScript 分析和安全分析。它将浏览器自动化、Chrome DevTools 协议调试、网络监控、智能 JavaScript 钩子、LLM 驱动的代码分析、进程和内存检查、WASM 工具、源码映射(source-map)重建、AST 转换以及复合工作流集成在单个服务器中。

文档 / 快速链接

Related MCP server: JS Reverse Strong MCP

🚀 快速开始

无需全局安装,即可在 Claude Desktop 或 Cursor 中立即使用 jshookmcp。

Claude Desktop 配置 (claude_desktop_config.json):

{
  "mcpServers": {
    "jshook": {
      "command": "npx",
      "args": ["-y", "@jshookmcp/jshook@latest"],
      "env": {
        "JSHOOK_BASE_PROFILE": "search"
      }
    }
  }
}

(Windows 用户注意:如果找不到 npx,请指定 npx.cmd 的绝对路径)

🌟 主要亮点

  • 🤖 AI 驱动的分析:利用 LLM 进行智能 JavaScript 反混淆、加密算法检测和 AST 级别的代码理解。

  • ⚡ 搜索优先的上下文效率:基于 BM25 的 search_tools + 动态增强,将 jshook 的工具模式初始化增量从约 40.0K+ tokens (full) 降低至约 3.0K (search)(Claude 服务器端计数;不包含 Claude Code 基础提示词)。

  • 🎯 渐进式能力分层:内置三种配置文件 (search/workflow/full),其中 search 作为按需扩展能力的默认基础层。

  • 🌐 全栈自动化:将 Chromium/Camoufox 浏览器、CDP 调试和网络拦截无缝编排为原子操作。

  • 🛡️ 高级反调试:内置针对 debugger 语句、时间检查和严格的无头机器人指纹识别技术的规避手段。

  • 🧩 动态扩展性:无需重新编译核心服务器,即可从本地目录热重载插件和工作流。

  • 🔧 零接线扩展性:通过 manifest.ts 自动发现域、延迟处理程序实例化,以及插件/工作流的 B-Skeleton 合约。

  • 🛠️ 逆向工程工具链:集成了 WASM 反汇编、二进制熵分析、内存扫描,以及 Burp Suite/Ghidra/IDA Pro 的桥接器。

🛡️ 核心能力

JSHookMCP 在 36 个领域提供了 360+ 个原子工具,为 AI 编排器提供了无与伦比的能力:

  • 🕸️ 浏览器自动化与逆向工程:零配置 Chromium/Camoufox 注入、CDP (Chrome DevTools Protocol) 编排以及 iframe 评估绕过。

  • 📡 网络拦截与欺骗:深度 HTTP/2 帧构建、MiTM 流量捕获、GraphQL 内省以及 Burp Suite 桥接。

  • 🧠 AST 与语义分析:LLM 驱动的反混淆、WebAssembly (WASM) 反汇编、Source Map 重建以及二进制熵可视化。

  • 🧰 进程与内存取证:原生 Frida 插桩、内存扫描、指针解引用以及严格的反调试缓解措施。

  • 🔌 动态扩展性:可热重载的 B-Skeleton 插件和声明式 WorkflowContract 流水线。

查看完整的 36 个领域工具目录 ↗

架构与性能

[!TIP] 上下文效率基准:内置工具模式初始化增量(Claude 服务器端计数):search ≈ 3.0K tokens vs full ≈ 40.0K+ tokens。

  • 渐进式工具发现:search_tools 元工具 (BM25 排名) + activate_tools / activate_domain + 基于配置文件的层级升级 (boost_profile)

  • 搜索层行为:search_tools 仅搜索并对结果进行排名;它不会自动运行 activate_tools,也不会自动运行 boost_profile。推荐链:search_tools -> activate_tools / activate_domain -> 仅在需要时使用 boost_profile

  • 不要为单个工具进行增强:activate_tools 可以从当前基础层跨层级注册精确工具;当您预期重复使用一系列相关的广泛工具时,boost_profile 效果更好

  • 延迟域初始化:处理程序类在首次调用时通过 Proxy 实例化,而不是在启动时

  • 域自发现:运行时清单扫描 (domains/*/manifest.ts) 取代了硬编码导入;通过创建一个清单文件即可添加新域

  • B-Skeleton 合约:插件 (PluginContract)、工作流 (WorkflowContract) 和可观测性 (InstrumentationContract) 的扩展性合约

  • MCP 工具注解:每个工具都带有语义注解 (readOnlyHint, destructiveHint, idempotentHint, openWorldHint),使 AI 编排器能够在调用前推断工具的安全性和副作用

注册表快照

下方的内置表面由运行时注册表生成,并在 CI 中进行检查。

  • 包版本:0.3.0

  • 内置工具:387

  • 域:adb-bridge, antidebug, binary-instrument, boringssl-inspector, browser, canvas, coordination, core, cross-domain, debugger, encoding, evidence, extension-registry, graphql, hooks, instrumentation, macro, maintenance, memory, mojo-ipc, network, platform, process, protocol-analysis, proxy, sandbox, shared-state-board, skia-capture, sourcemap, streaming, syscall-hook, trace, transform, v8-inspector, wasm, workflow

  • 注意:此快照由运行时注册表生成;请勿手动编辑计数。

查看完整的工具参考 ↗

项目统计

Star 历史

Activity

Available Tools

7 tools
activate_domainB

Activate all tools in a domain at once. Domains: . Use reload_extensions first to include external plugin/workflow domains.

ParametersJSON Schema
NameRequiredDescriptionDefault
domainYesDomain name to activate (e.g. "debugger", "network")
ttlMinutesNoAuto-deactivate after N minutes (default: 30, set 0 for no expiry)

TDQS

B3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must bear the burden of disclosing behavior. The description only states the basic action and a prerequisite, but does not mention any side effects, permissions, or reversibility of activation. It also has a broken placeholder 'Domains: .'.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is short (2 sentences), but includes a confusing broken fragment 'Domains: .' which detracts from conciseness. It is front-loaded with the main action but ends with an incomplete thought.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the lack of annotations and output schema, the description should provide more context, such as the list of available domains or what 'activation' entails. It fails to do so, leaving the user uncertain about the domains that can be activated.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 100% description coverage for both parameters, so the description does not need to add much. It does not elaborate on the parameters beyond the schema, so it meets the baseline for no added value.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action: 'Activate all tools in a domain at once.' It distinguishes from siblings like 'activate_tools' (which likely activates individual tools) by specifying it operates on a whole domain. However, the incomplete sentence 'Domains: .' reduces clarity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives a prerequisite: 'Use reload_extensions first...', which implies when to use it. But it does not explicitly contrast with alternatives like 'activate_tools' or state when not to use this tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

activate_toolsA

Dynamically register specific tools by name, regardless of current base tier. Use after search_tools to enable exactly the tools you need. In search-tier sessions this is usually enough; you do not need boost_profile just to use a few exact tools. Activated tools appear in the tool list immediately. If tools do not appear after activation, use call_tool to invoke them directly.

ParametersJSON Schema
NameRequiredDescriptionDefault
namesYesArray of tool names to activate (from search_tools results)

TDQS

A4.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, description discloses that activation makes tools appear immediately and suggests direct invocation if not. Lacks details on side effects or permissions, but adequately covers expected behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Multiple sentences but no waste; core action front-loaded. Could be slightly shorter, but structure is effective.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given simple input, no output schema, the description explains activation behavior, usage pattern, and recovery step, making it fully self-contained.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, but description adds context by referencing search_tools as source for names, reinforcing parameter meaning beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states the tool dynamically registers tools by name, and distinguishes from siblings like search_tools and call_tool. It also compares to boost_profile, providing clear purpose.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly says to use after search_tools, notes it's usually enough without boost_profile, and provides fallback using call_tool if activation fails.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

call_toolA

Execute an already-active tool by name. Use this when activate_tools/activate_domain registered a tool but your client did not refresh its tool list. Does not auto-activate inactive tools.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesThe tool name to execute (from search_tools or describe_tool results)
argsNoArguments object to pass to the tool

TDQS

A3.7/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided, so description must fully disclose behaviors. It only states it executes active tools and does not auto-activate, omitting error handling, auth needs, rate limits, or what happens if tool not found.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, front-loaded with main purpose and usage context, no wasted words. Perfectly concise.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Covers core purpose and limitation but lacks details on error cases, return value, or validation of args. Given no output schema, more behavioral context would be helpful.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Input schema has 100% description coverage for both parameters (name and args), so the description adds little beyond schema. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states the verb 'execute' and resource 'already-active tool', and distinguishes from sibling tools like activate_tools and deactivate_tools by specifying it does not auto-activate inactive tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly describes when to use (after activation when client didn't refresh) and implies when not to use (tool not active). Could mention alternatives like activate_tools for inactive tools, but is still clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

deactivate_toolsA

Remove previously activated tools to free context. Only affects tools added via activate_tools, not base profile tools.

ParametersJSON Schema
NameRequiredDescriptionDefault
namesYesArray of tool names to deactivate

TDQS

A4.1/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It discloses that the tool removes tools and frees context, but does not mention side effects, permissions, or reversibility. The behavioral transparency is adequate but not detailed.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences, front-loaded with the action, and contains no unnecessary words. Every sentence adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the simple input schema (one required array parameter) and no output schema, the description adequately explains the tool's effect and scope. It is complete for the tool's straightforward purpose.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 100% coverage with a description for the 'names' parameter: 'Array of tool names to deactivate'. The overall description adds context that these are tools activated via activate_tools, but this is already implied by the tool's purpose. The schema does the heavy lifting, so the description adds limited additional meaning.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool removes previously activated tools to free context, specifying the verb 'remove' and the resource 'previously activated tools'. It distinguishes from siblings by clarifying it only affects tools added via activate_tools, not base profile tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states that the tool only affects tools added via activate_tools, not base profile tools, providing clear guidance on when to use it. It implies it is the counterpart to activate_tools, but does not explicitly mention alternatives or when not to use it beyond that scope.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

describe_toolA

Get detailed information about a specific tool, including its input schema. Use this to see the exact parameters a tool expects before calling it.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesTool name to describe

TDQS

A4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided; description accurately states it retrieves tool info and input schema, but offers no additional behavioral context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Single sentence, front-loaded with purpose, no redundant words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Sufficient for a simple tool with one parameter and no output schema; could mention return format but not essential.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Parameter 'name' already described in schema (100% coverage); description adds no extra meaning beyond schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clear verb 'Get' and resource 'detailed information about a specific tool', distinct from sibling tools like call_tool or search_tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly suggests using before calling another tool to inspect parameters, but lacks explicit when-not-to-use guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

route_toolA

One-stop tool router: accepts a natural language task description, returns recommended tools and next actions. Automatically detects workflow patterns, recommends activation order, and provides example arguments. Use this instead of search_tools when you want guided tool discovery with actionable next steps.

ParametersJSON Schema
NameRequiredDescriptionDefault
taskYesNatural language description of the task you want to accomplish
contextNoOptional context hints for routing

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided, so description fully carries behavioral disclosure. It explains that the tool detects workflow patterns, recommends activation order, and provides example arguments, going beyond simple I/O to explain internal processing.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences with clear front-loading: first sentence defines purpose, second sentence adds usage guidance. No redundant information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema; description mentions 'returns recommended tools and next actions' but lacks details on output format, structure, or how to interpret results. For a tool whose primary output is recommendations, this is a notable gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with clear descriptions for 'task' and 'context'. Description does not add further semantic detail beyond what schema already provides, so baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states tool is a router that accepts a task description and returns recommended tools/actions. It explicitly distinguishes from sibling search_tools, providing specific verb+resource: natural language task to tool recommendations.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly says 'Use this instead of search_tools when you want guided tool discovery with actionable next steps', providing clear context for when to use this tool. Could be stronger by stating conditions for using alternatives like search_tools.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

search_toolsA

Search 0 tools across 0 capability domains. This includes built-in tools plus any loaded plugin/workflow tools (0 currently loaded). In search-tier sessions, call this before assuming a capability is unavailable. Use activate_tools for exact matches, activate_domain for an entire domain. Domains: . Query tip: before searching, distill your intent into key concepts (action verb + target + domain). Pass distilled keywords, not full sentences — the search engine works on token matching, not semantic understanding.

ParametersJSON Schema
NameRequiredDescriptionDefault
queryYesBefore calling, distill your intent into 2-5 key concepts: what action, on what target, in which domain. Pass only those distilled keywords — not the original user request.
top_kNoMax results to return (default: 10, max: 30)

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description adds behavioral context: it explains how the search engine works ('token matching, not semantic understanding') and provides a query formulation tip. However, it does not disclose potential limitations or exact return format.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single paragraph with multiple sentences. While each sentence provides useful information, it is slightly verbose and could be more streamlined. However, it is still relatively concise and front-loaded with key information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool has two parameters, no output schema, and no annotations, the description covers purpose, usage guidance, query optimization, and sibling differentiation. It lacks details on result structure or pagination, but overall it is fairly complete for a search tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with both parameters documented. The description adds value beyond schema by providing guidance on how to construct the query parameter (distill intent into key concepts) and clarifying the default and max for top_k. This adds meaning not present in the schema alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose as searching tools across capability domains, including built-in and plugin/workflow tools. It distinguishes itself from sibling tools like activate_tools and activate_domain by specifying that it is for searching, not activating.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly advises when to use this tool: 'In search-tier sessions, call this before assuming a capability is unavailable.' It also provides alternatives: 'Use activate_tools for exact matches, activate_domain for an entire domain.'

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 7 tool updatesv0.3.0
    • First observedactivate_domain
    • First observedactivate_tools
    • First observedcall_tool
    • First observeddeactivate_tools
    • First observeddescribe_tool
    • First observedroute_tool
    • First observedsearch_tools

TDQS

A4/5.0

Scored across 7 tools

Disambiguation4/5

Tools have mostly distinct purposes, but activate_domain and activate_tools overlap in activation functionality, and route_tool overlaps with search_tools in discovery. Descriptions help differentiate.

Naming Consistency5/5

All tools follow a consistent verb_noun pattern (e.g., activate_domain, search_tools), making predictions easy.

Tool Count5/5

7 tools is well-scoped for a tool management server, covering all necessary operations without being excessive.

Completeness5/5

Covers activation, deactivation, search, description, routing, and calling. No obvious gaps in the tool management lifecycle.

Maintenance

ActivityActive
ResponsivenessResponsive

Related MCP Connectors

Related MCP Servers