Jshookmcp MCP server
MCP server for JavaScript analysis, security auditing, browser automation and hooks
2.0k stars857 downloads/wk
Reviews
Write oneNobody has reviewed Jshookmcp yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Jshookmcp tools (9, 2 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
activate_domainActivate all tools in a domain at once. Domains: …. Use reload_extensions first to include external plugin/workflow domains.
activate_toolsDynamically register specific tools by name, regardless of current base tier. Use after search_tools to enable exactly the tools you need. In search-tier sessions this is usually enough; you do not need boost_profile just to use a few exact tools. Activated tools appear in the tool list immediately. If tools do not appear after activation, use call_tool to invoke them directly.
call_toolwrite actionExecute an already-active tool by name. Use this when activate_tools/activate_domain registered a tool but your client did not refresh its tool list. Does not auto-activate inactive tools.
deactivate_toolswrite actionRemove previously activated tools to free context. Only affects tools added via activate_tools, not base profile tools.
describe_toolGet detailed information about a specific tool, including its input schema. Use this to see the exact parameters a tool expects before calling it.
route_toolOne-stop tool router: accepts a natural language task description, returns recommended tools and next actions. Automatically detects workflow patterns, recommends activation order, and provides example arguments. Use this instead of search_tools when you want guided tool discovery with actionable next steps.
skia_correlate_objectsCorrelate requested Skia node identifiers with the extracted scene tree.
skia_detect_rendererDetect the active Skia renderer backend from the current page context.
skia_extract_sceneExtract a lightweight Skia scene tree from the selected canvas.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan159 source files scanned10/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (3)
- mediumnpm install lifecycle script present
install.script - mediumeval / new Function used
exec.evaldist/ConsoleMonitor-DykL3IAw.mjs: … console.log('[ScriptMonitor] eval() called with code:', typeof… - mediumnpm install lifecycle script present
install.scriptpackage.json: …shOnly": "corepack pnpm run check", "postinstall": "node scripts/postinstall.cjs", "in…
Install Jshookmcp in Claude Code, Cursor or VS Code
Runs npx -y @jshookmcp/jshook on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add jshookmcp -- npx -y @jshookmcp/jshook
What the publisher says
From the Jshookmcp repository's README, as published. We do not edit it. Read it on GitHub
@jshookmcp/jshook
A search-first, profile-aware reverse-engineering workspace for AI agents.
Hook the page, capture the network, deobfuscate the bundle, disassemble the WASM, instrument the process — and let one MCP server keep the whole attack surface in reach without drowning the model in schemas.
English · 中文
<!-- npm badge: re-add once @jshookmcp/jshook is published -->
What's different · Capabilities · Use cases · Highlights · Transport · Registry · Architecture · Build
Documentation · Getting Started · Configuration · Tool Reference
Sponsored by Swiftproxy — Premium Residential Proxies for Web Automation · 10% off code: PROXY90
What makes jshook different
Most MCP servers for JS analysis expose a handful of hand-rolled tools or wrap a single browser engine. jshook is closer to an operating system for front-end reverse engineering — 36 self-discovered domains, a search-first meta-tool that keeps token cost under control, and runtime recovery that survives broken pages and dropped sessions:
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Jshookmcp: common questions
- Is Jshookmcp MCP server safe?
- With care: it is graded C, so read the findings first (69/100). Read the Jshookmcp safety report
- How do I install Jshookmcp?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Jshookmcp need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Jshookmcp maintained?
- The last commit was in the last day (2026-09-27). The latest release is v0.3.0.
- What can I use instead of Jshookmcp?
- Servers from other publishers that do the same job: Reddit Buddy MCP server, SeleniumBase MCP server and AIHawk MCP server. Compare all Jshookmcp alternatives.
Alternatives to Jshookmcp
Same job from other publishers: the closest match first, then the best rated.
- Reddit BuddyReddit browser for AI assistants. Browse without API keys; add credentials for search and analysis.not reviewedEstablishedA
- SeleniumBase MCPStealthy browser automation, testing, and web-scraping via CDP Mode.not reviewedWidely usedA
- AIHawkAI browser agent: browses, clicks, types, and reads real web pages from plain-English instructions.not reviewedWidely usedA
- Browser UseControl a real Chrome browser to complete any task: fill forms, extract data, book flights.not reviewedEstablishedA
- SkyvernAI-powered browser automation — navigate, click, fill forms, and extract data from any website.not reviewedEstablishedA