Skip to main content
Glama
kings0527

WebTrace MCP Server

by kings0527

WebTrace

AI-driven JSVMP Auto-Reversal Chrome/Edge Extension with MCP Server

Features

  • MCP Server: Expose reverse engineering capabilities via MCP protocol for AI Agents

  • JSVMP Auto-Detection: Automatically identify VM dispatch loops (while-switch/if-else/handler-table)

  • QuickJS WASM Sandbox: Execute and trace JSVMP bytecode in isolated environment

  • Stealth Engine: Three-layer stealth (Extension hiding + Proxy Hook cloaking + Timing alignment)

  • Babel AST Instrumentation: Auto-instrument VM dispatch loops for trace collection

  • Cross-browser: Chrome & Edge (Manifest V3)

Related MCP server: ghidraMCP

Quick Start

Build

npm install
npm run build

Load Extension

  1. Open chrome://extensions/

  2. Enable "Developer mode"

  3. Click "Load unpacked" → select dist/ directory

Connect AI Agent

See docs/SKILL-INTEGRATION.md

Connect Codex CLI

WebTrace now includes a local stdio bridge for MCP clients that cannot connect to an Edge extension RuntimePort directly. The bridge listens for the extension at ws://127.0.0.1:3100/mcp and proxies MCP JSON-RPC over stdio to Codex. If the port is already used by another Codex session, the bridge automatically tries the next ports in the range.

codex mcp add webtrace -- node /Users/kk/git/web-trace/bin/webtrace-codex-bridge.mjs

After changing extension code, rebuild and reload the unpacked extension in edge://extensions. The extension service worker automatically connects to the bridge port range when Codex starts it, so multiple Codex sessions can use WebTrace at the same time.

Architecture

┌─────────────────────────────────────────────────────┐
│                   AI Agent (MCP Client)              │
│            Qoder / Cursor / Claude Code             │
└────────────────────┬────────────────────────────────┘
                     │ MCP Protocol (WebSocket/Port)
┌────────────────────▼────────────────────────────────┐
│              Service Worker (Background)              │
│  ┌─────────┐  ┌──────────┐  ┌──────────────────┐   │
│  │MCP Server│  │Tab Manager│  │Offscreen Manager │   │
│  └─────────┘  └──────────┘  └────────┬─────────┘   │
└───────────────────────────────────────┼─────────────┘
                                        │
┌───────────────────────────────────────▼─────────────┐
│              Offscreen Document                       │
│  ┌──────────────────┐  ┌─────────────────────────┐  │
│  │QuickJS WASM      │  │Babel AST Engine         │  │
│  │(Sandbox + Trace) │  │(Detect + Instrument)    │  │
│  └──────────────────┘  └─────────────────────────┘  │
└─────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────┐
│              Target Web Page                          │
│  ┌────────────┐  ┌────────────┐  ┌──────────────┐  │
│  │Stealth     │  │VM Tracer   │  │API Hooks     │  │
│  │Bootstrap   │  │(Proxy)     │  │(fetch/XHR)   │  │
│  └────────────┘  └────────────┘  └──────────────┘  │
└─────────────────────────────────────────────────────┘

MCP Tools

Tool

Description

detect_protection

Detect page protection type and level

analyze_jsvmp

Analyze JSVMP code structure

trace_execution

Execute in sandbox with full trace

extract_bytecode

Extract bytecode arrays from page

hook_api

Set up API hooks on page

get_hook_logs

Retrieve hook logs

page_state

Get page state (cookies/storage/scripts), optionally by tabId or url

list_tabs

List browser tabs, including window and incognito metadata

activate_tab

Activate a tab by tabId

navigate

Navigate the current tab, a target tab, or a new tab

dom_snapshot

Read visible text, forms, inputs, buttons, and links from a tab

query_dom

Query DOM nodes by CSS selector

deobfuscate

Deobfuscate JS code

For InPrivate/incognito pages, Edge must allow the extension in InPrivate mode. Site access set to "all sites" is not enough by itself.

Integration

Tech Stack

  • TypeScript + Vite

  • Chrome Extension Manifest V3

  • MCP (Model Context Protocol)

  • QuickJS WASM (quickjs-emscripten)

  • Babel AST (@babel/parser + traverse)

License

MIT

F
license - not found
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    A
    maintenance
    An MCP server for JavaScript reverse engineering that enables AI to perform browser debugging, script analysis, and automated hook injection. It streamlines complex workflows like deobfuscation, network tracing, and risk assessment through direct browser integration.
    Last updated
    16
    903
    Apache 2.0
  • A
    license
    -
    quality
    D
    maintenance
    An Model Context Protocol server that enables LLMs to autonomously reverse engineer applications by exposing Ghidra's decompilation and analysis tools. It allows AI agents to list code structures, rename methods, and analyze binaries directly through MCP-compatible clients.
    Last updated
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    An anti-detection browser MCP server designed for JavaScript reverse engineering through the Camoufox engine. It enables AI assistants to perform dynamic debugging, function hooking, and network interception while bypassing sophisticated bot detection mechanisms.
    Last updated
    35
    389
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    Exposes Ghidra reverse engineering capabilities via MCP, enabling LLMs and agents to analyze binaries, decompile, search, and edit programs headlessly or with GUI integration.
    Last updated
    386
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • Reasoning, code, anti-deception, memory harness MCP tools. Stdio or HTTPS api.ejentum.com/mcp

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

  • OCR, transcription, file extraction, and image generation for AI agents via MCP.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/kings0527/web-trace'

If you have feedback or need assistance with the MCP directory API, please join our Discord server