New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

Jshookmcp

736 tools. 388 can modify or destroy data without limits.

29 destructive tools with no built-in limits. Policy required.

Last updated:

388 can modify or destroy data
348 read-only
736 tools total

Community server · catalogue entry checked 27/09/2026

How to control Jshookmcp ↓

What Jshookmcp exposes to your agents

Read (348) Write / Execute (359) Destructive / Financial (29)
Critical Risk

The most dangerous Jshookmcp tools

388 of Jshookmcp's 736 tools can modify, destroy, or commit something on every call — and an agent calls them with no built-in limits.

How to control Jshookmcp

PolicyLayer is an MCP gateway — it sits between your AI agents and Jshookmcp, and nothing reaches the server without passing your rules. These are the rules we recommend:

Deny destructive operations
{
  "adb_uninstall": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Blocked by default. Requires approval."
      }
    ]
  }
}

Destructive tools should never be available to autonomous agents without human approval.

Rate limit write operations
{
  "adb_file_push": {
    "limits": [
      {
        "counter": "adb_file_push_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "adb_apk_analyze": {
    "limits": [
      {
        "counter": "adb_apk_analyze_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

  1. Create a free account and register Jshookmcp — nothing to install.
  2. Add these rules — paste them, or build them visually. Tune the limits to your setup.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
ENFORCE POLICY ON JSHOOKMCP →

Instant setup, no code required.

All 736 Jshookmcp tools

DESTRUCTIVE 29 tools
Destructive adb_uninstall Uninstall a package from a device, optionally keeping app data. Destructive cleanup_artifacts Clean generated artifacts by age and size. Destructive clear_all_caches Clear all internal caches. Destructive — prefer smart_cache_cleanup. Destructive clear_collected_data Clear collected script data, caches, and in-memory indexes. Destructive dart_destroy_session Destroy a Dart snapshot session created by dart_create_session, releasing the cached parsed snapshot. Returns Destructive exploit_cache_clear Clear all cached exploit-dev results. Use when binaries have been modified or to free memory. Destructive exploit_cache_invalidate Invalidate cached exploit-dev results for a specific binary (by path). Computes the binary hash and removes al Destructive extension_uninstall Uninstall an extension from the local registry. Destructive ghidra_decompile Decompile a function using Ghidra. Destructive ida_decompile Decompile a function using IDA Pro. Destructive jadx_decompile_apk High-level JADX APK decompile: decompile the whole APK to a stable output directory and return sourcesDir for Destructive manual_token_cleanup Clear stale entries and reset counters to free 10-30% of token budget. Destructive memory_antidetection Anti-detection hardening toolkit. Actions: check (run all detectors — kernel callbacks, instrumentation callba Destructive memory_batch_edit Write a value to ALL addresses in a scan session at once. Thin wrapper that iterates through the session addre Destructive memory_scan_session Manage scan sessions. Actions: list (all sessions), delete (by sessionId), export (as JSON). Destructive memory_unregister_type Remove a registered custom scan type by name. Destructive nemu_destroy_session Destroy an emulator session and free its memory (mapped library, stack, JNI tables). Destructive page_cookies Manage page cookies; clear requires matching expectedCount. Destructive page_local_storage Read, write, delete, or clear localStorage entries for the current origin. Destructive page_session_storage Read, write, delete, or clear sessionStorage entries for the current origin. Destructive proxy_clear_logs Clear all captured proxy request/response logs. Destructive proxy_clear_rules Clear active proxy interception rules while keeping the proxy running. Destructive proxy_remove_rule Remove a single proxy interception rule by endpointId. Returns the removed rule record. Destructive reset_token_budget Hard-reset all token budget counters. Destructive — prefer manual_token_cleanup. Destructive session_progress_clear Clear session progress entries. With no Destructive snapshot_restore Restore a directory to a recorded shadow-git snapshot. DESTRUCTIVE: files modified after the snapshot are over Destructive tls_keylog_seal Encrypt the current keylog file in place with a fresh ephemeral key and securely wipe the plaintext source. Mi Destructive v8_heap_snapshot_delete Delete persisted V8 heap snapshot artifact files (.heapsnapshot data + .meta.json sidecar) and drop the matchi Destructive webhook Manage webhook endpoints for external callbacks. Actions: create, list, delete, commands.
EXECUTE 289 tools
Execute activate_tools Dynamically register specific tools by name, regardless of current base tier. Execute adb_app_cold_start_trace High-level Android startup trace: force-stop, clear logcat, start activity with -W, wait, collect PID-filtered Execute adb_dumpsys Run adb shell dumpsys for a service and return parsed structured output. Supports key-value extraction, array Execute adb_input_keyevent Send an Android keyevent name or numeric key code through adb shell input. Execute adb_input_swipe Send a touchscreen swipe event through adb shell input. Execute adb_input_tap Send a touchscreen tap event through adb shell input. Execute adb_input_text Send text through adb shell input text with Android-safe whitespace encoding. Execute adb_install Install one APK or a split-APK set onto a device with parsed success output. Execute adb_port_forward Manage ADB forward/reverse port mappings for device-host bridge workflows. Execute adb_shell Execute an ADB shell command on a specific device. Execute adb_webview_attach Attach to a WebView via ADB; returns WebSocket debugger URL for CDP. Execute ai_hook Manage AI hooks. Actions: inject (inject code into page), get_data (retrieve captured hook data), list (all ac Execute analysis_deflat_control_flow Flatten switch-dispatch control flow back to straight-line code. Execute antidebug_bypass Bypass one or more anti-debug protection types. Specify types to apply; omit or use [ Execute api_probe_batch Batch-probe API endpoints in browser context with auto token injection and HTML skip. Execute apk_sign Sign an APK with apksigner using a caller-supplied keystore. Pairs with apktool_build for a full repack-and-si Execute apktool_build Rebuild an APK from a decoded apktool source directory (closes the patch-and-repack loop with apk_sign). Execute arp_build Build a deterministic ARP payload for Ethernet/IPv4. Execute ast_transform_apply Apply transforms to input code or a live page scriptId. Execute ast_transform_chain Create and store an in-memory transform chain. Execute binary_ninja_bridge Send a command to a local Binary Ninja analysis bridge. Execute breakpoint Manage breakpoints: code (line/script), function-name, XHR (URL pattern), event listener, event category, and Execute browser_attach Connect to a running browser. Execute browser_attach_cdp_target Attach to a CDP target by targetId. Execute browser_close Close the browser and release all resources. Execute browser_codegen_start Start recording browser actions as replayable steps. Execute browser_codegen_stop Stop recording browser actions and return cleaned replay steps. Execute browser_cpu_profile_start Atomic primitive: begin CDP CPU profiling on the active page (Profiler.start). Pair with browser_cpu_profile_s Execute browser_cpu_profile_stop Atomic primitive: stop CDP CPU profiling, rank hot functions by sample count, and persist the raw profile to a Execute browser_detach_cdp_target Detach the current CDP target session. Execute browser_evaluate_cdp_target Evaluate JS in the attached CDP target. Execute browser_jsdom_execute Evaluate JS inside a JSDOM session. Requires explicit authorization — arbitrary code execution. Execute browser_jsdom_parse Parse HTML into an in-memory JSDOM session. No browser needed. Execute browser_launch Launch Chromium/Camoufox or connect to a running browser. Execute browser_performance_observer Atomic primitive: subscribe to PerformanceObserver entry types in the active page and return both buffered and Execute browser_select_tab Switch active tab by index, URL pattern, or title pattern. Execute browser_trace_start Atomic primitive: begin a Chrome performance trace on the active page via page.tracing.start(). Pair with brow Execute browser_trace_stop Atomic primitive: stop the Chrome performance trace started by browser_trace_start and persist it to artifacts Execute call_tool Execute an already-active tool by name. Execute camoufox_server Start, close, or check status of a Camoufox anti-detect server. Execute canvas_inject_draw_hook Intercept Canvas 2D (drawImage/fillText/strokeText) and WebGL (drawArrays/drawElements) draw calls into a ring Execute canvas_trace_click_handler Trace a click event from DOM to JS call stack. Execute captcha_vision_solve Solve a CAPTCHA with manual flow or a configured external service. Execute captcha_wait Block until the user manually solves the CAPTCHA. Execute console_buffers Manage injected interceptor state. Execute console_execute Evaluate a JS expression in the browser console context. Execute console_inject Inject an in-page script, XHR, fetch, or function monitor. Execute console_inject_fetch_interceptor Inject a fetch interceptor. Execute console_inject_xhr_interceptor Inject an XMLHttpRequest interceptor. Execute cross_domain_correlate_all Run the built-in skia, mojo, syscall, and binary correlators and merge the results into the shared evidence gr Execute crypto_extract_standalone Extract crypto/sign/encrypt function from current page and generate standalone runnable code. Execute crypto_test_harness Run extracted crypto code in worker_threads + vm sandbox and return deterministic test results. Execute dart_call_function Execute a Dart function in the ARM64 emulator by address or name, with simplified runtime (mock built-ins, tag Execute dart_create_session Parse a Dart AOT snapshot once and cache it under a sessionId, so subsequent dart_load_snapshot / dart_list_fu Execute dart_trace_execution Trace Dart function execution step-by-step, emitting each instruction with register state (PC, x0-x30, PP, THR Execute debugger_evaluate Evaluate a JavaScript expression. context= Execute debugger_lifecycle Enable or disable the CDP debugger session. Execute debugger_pause Pause execution at the next statement. Execute debugger_resume Resume execution. Execute debugger_run_to_location Run execution until a source location by setting a temporary code breakpoint, resuming, waiting for pause, and Execute debugger_step Step execution: into (enter next call), over (skip next call), out (exit current function). Execute debugger_wait_for_paused Wait for debugger pause after setting breakpoints. Execute deobfuscate Run webcrack-powered JavaScript deobfuscation with bundle unpacking. Execute doctor_environment Run environment doctor: dependencies, bridges, platform limits. Execute electron_attach Attach to an Electron CDP port and optionally evaluate in a matching page. Execute electron_launch_debug Launch Electron with main and renderer CDP ports. Execute electron_patch_fuses Patch Electron fuse states. Execute ethernet_frame_build Build a deterministic Ethernet II frame from source/destination MAC addresses, EtherType, and payload bytes. Execute execute_sandbox_script Execute JavaScript in an isolated sandbox. Execute exploit_build_format_string Generate format string exploit payload for arbitrary write. Uses %hn (2-byte) writes for reliability. Returns Execute exploit_build_heap_spray Generate heap spray payload for predictable heap layout. Supports V8 (ArrayBuffer), IE (BSTR), and generic (Ar Execute exploit_build_jop_chain Build a JOP (Jump-Oriented Programming) chain from binary gadgets. Execute exploit_build_ret2dlresolve Build a ret2dlresolve payload that forges ELF dynamic-linker structures to resolve Execute exploit_build_rop_chain Construct a ROP chain for a specified goal (execve, write_memory, call_function). Automatically searches for r Execute exploit_build_stack_pivot Find and assemble stack pivot gadgets from a binary. Stack pivots redirect the stack pointer (ESP/RSP) to a co Execute exploit_cache_configure Update exploit-dev cache configuration (TTLs, memory limits, enable/disable). Changes take effect immediately. Execute exploit_calculate_offsets Calculate buffer overflow offset from crash value and De Bruijn pattern. Used to determine exact EIP/RIP overw Execute exploit_discover_one_gadget Discover one-gadget (single-address shell-spawning) offsets for common libc versions. Execute exploit_encode_shellcode Encode shellcode to avoid bad characters or detection. Supports alphanumeric, unicode, XOR, and fnstenv encodi Execute exploit_find_gadgets Search for ROP/JOP/COP/COOP gadgets in a binary file. Returns addresses, instructions, and bytes for each gadg Execute exploit_find_jmp_esp Find Execute exploit_generate_egghunter Generate egghunter shellcode for constrained buffer sizes. An egghunter searches process memory for a 4-byte Execute exploit_generate_pattern Generate De Bruijn sequence for offset finding. Every 4-byte substring is unique, allowing precise offset calc Execute exploit_generate_pwntools Generate a pwntools-compatible Python exploit script (exploit.py). Execute exploit_solve_constraints Solve a system of constraints using the Z3 SMT solver. Execute exploit_verify_rop_chain Verify a user-supplied ROP chain against an exploit goal using Z3. Execute extension_execute_in_context Load an extension and execute a named exported context function. Execute extension_install Install/register an extension from a manifest, local package directory, local module file, or remote module UR Execute extension_reload Reload an installed extension by unloading and loading it again. Execute fetch_stream_monitor Enable or disable capture of fetch()-based streams. Wraps window.fetch and, for responses with content-type te Execute frida_attach Attach Frida to a local target and open a session. Execute frida_attach_interceptor Generate a real Frida Interceptor.attach block for a symbol and optionally install it in a session. Execute frida_detach Detach from a Frida session and clean up resources. Execute frida_dex_dump Run frida-dexdump as a high-level Android DEX dump helper by package/process name or PID. Execute frida_generate_script Generate a Frida interceptor or hook script from built-in templates. Execute frida_memory_scan Scan process memory for a byte pattern via Frida Memory.scanSync. Searches a named module, an explicit address Execute frida_resume Resume a target previously spawned for early Frida instrumentation. Execute frida_run_script Execute a Frida JavaScript snippet inside an attached Frida session. Pass async:true to run in a background ta Execute frida_spawn Spawn a target through Frida for early instrumentation before normal execution. Execute generate_hooks Generate a Frida interceptor script for a list of symbols. Execute ghidra_bridge Send a command to a Ghidra headless analysis bridge. Execute graphql_replay Replay a GraphQL operation with optional variables, batch array, or Apollo persisted-query (APQ) extensions. Execute graphql_subscribe Open a GraphQL subscription WebSocket, perform the graphql-transport-ws (or legacy graphql-ws) handshake, send Execute grpc_frame_build Encode one or more messages into a gRPC / gRPC-Web length-prefixed body. Inverse of grpc_frame_parse — for con Execute hook_preset Install a pre-built JavaScript hook from 20+ built-in presets (eval, atob/btoa, Proxy, Reflect, Object.defineP Execute http_plain_request Send a raw HTTP request over plain TCP. Execute http_request_build Build a raw HTTP/1.x request payload. Execute http2_frame_build Build a raw HTTP/2 frame. Execute http2_probe Probe an HTTP/2 endpoint. Execute human_mouse Move mouse along a Bezier curve with jitter. Execute human_scroll Scroll with randomized speed and pauses to mimic human behavior. Execute human_typing Type text with human-like speed and occasional typos. Execute icmp_echo_build Build a deterministic ICMPv4 echo request or reply payload with an automatically computed checksum. Execute ida_bridge Send a command to an IDA Pro plugin bridge. Execute inject_dll Inject a DLL into a target process. Requires elevated privileges. Target process and payload are validated bef Execute inject_shellcode Allocate and execute raw shellcode in a target process. Requires elevated privileges. Target process and paylo Execute install_extension Install an extension from the remote registry. Execute instrumentation_hook_preset Apply hook presets inside an instrumentation session. Execute instrumentation_network_replay Replay a captured network request inside an instrumentation session. Execute instrumentation_operation Manage operations inside an instrumentation session. Execute instrumentation_session Start, stop, or query status of an instrumentation recording session. Destroying a session archives it read-on Execute js_deobfuscate_pipeline Three-stage deobfuscation pipeline: preprocess → deobfuscate → humanize. Execute js_solve_constraints Solve opaque predicates and constant expressions in obfuscated code. Execute js_symbolic_execute Symbolic execution of JavaScript: explore all feasible execution paths, collect path constraints, and solve th Execute js_symbolic_execute_jsvmp Symbolic execution of JSVMP bytecode: step through instructions symbolically to infer original logic, constrai Execute manage_hooks Create, inspect, and clear JavaScript runtime hooks. Execute memory_allocate Allocate executable memory in target process (VirtualAllocEx wrapper). Win32 only. Requires JSHOOK_INJECTION_E Execute memory_auto_assemble Execute a Cheat Engine-style Auto Assembler script. Parses [ENABLE]/[DISABLE] sections and executes ENABLE com Execute memory_auto_assemble_disable Execute the DISABLE section of a previously-run Auto Assembler script. Pass the disableScript returned by memo Execute memory_batch_write Write multiple memory patches at once. If pid is omitted, the active browser renderer PID is auto-discovered f Execute memory_breakpoint Breakpoint via hardware debug registers (DR0-DR3) or software INT3 (0xCC). Actions: set, remove, list, trace. Execute memory_call_stack Walk the call stack of a target process thread using the x64 RBP frame-pointer chain. Suspends the thread, rea Execute memory_cheat_table Import, export, sign, or verify Cheat Engine .CT files. Export: converts JSON entries to valid .CT XML. Import Execute memory_find_accesses Find what writes to or accesses a memory address (Cheat Engine MWT workflow). Sets a hardware breakpoint on th Execute memory_first_scan Start a new memory scan session. Execute memory_free Free remote memory in target process (VirtualFreeEx wrapper). Win32 only. Requires JSHOOK_INJECTION_ENABLE=1. Execute memory_freeze Freeze or unfreeze a memory address. Freeze continuously writes a value to prevent changes; unfreeze stops it. Execute memory_hypervisor EPT Hypervisor Phase 1: VMXON, VMCS setup, basic VM-exit handler design, CPUID spoofing. Intel VT-x only. Requ Execute memory_inject_dll Inject a DLL into target process. Win32 only. Modes: loadlibrary (LoadLibraryW injection) or manualmap (manual Execute memory_inject_shellcode Inject shellcode into target process. Win32 only. Methods: createremote (CreateRemoteThread) or ntcreatethread Execute memory_next_scan Narrow an existing scan session. Supports delta modes: changed_by (value changed by exactly N), increased_by ( Execute memory_patch_bytes Write bytes to target process at address. Saves original bytes for undo. Use for runtime code patching. Execute memory_patch_nop NOP out instructions at address (replace with 0x90). Useful for disabling checks or jumps. Execute memory_pointer_chain Pointer chain operations: scan (multi-level BFS), autoscan (auto-discover pointer chains by recursively scanni Execute memory_process_control Suspend or resume a target process for consistent memory snapshots. Suspend freezes all threads (NtSuspendProc Execute memory_protect Change memory page protection for a region in the target process. Wraps VirtualProtectEx (Win32) / mprotect (L Execute memory_remote Connect to a remote jshookmcp MCP server via WebSocket for remote debugging. Enables ceserver-style remote mem Execute memory_scan Scan process memory for a pattern or value. Requires elevated privileges. If pid is omitted, the active browse Execute memory_speedhack Hook time APIs (GetTickCount64/GetTickCount/QueryPerformanceCounter/QueryPerformanceFrequency/timeGetTime/GetS Execute memory_trace_code Ultimap-style instruction-level code tracing. Sets INT3 (0xCC) software breakpoints at function entry points a Execute memory_unknown_scan Start an unknown initial value scan. Execute memory_watch Poll a memory address until its value changes (like scanmem\ Execute memory_write Write data to process memory at a given address. If pid is omitted, the active browser renderer PID is auto-di Execute memory_write_value Write a typed value to a memory address. Supports undo/redo via memory_write_history(action=undo|redo). Execute miniapp_pkg_unpack Unpack a miniapp package. Execute mojo_encode_message Encode a structured Mojo IPC message into a hex payload. Execute mojo_monitor Start or stop Mojo IPC monitoring for the active Chromium-based target. Execute mojo_verify_live Generate a Frida verification script that probes a target Chromium process for known Mojo C-API exports (MojoW Execute nemu_alloc_memory Allocate raw guest memory (NOT a JNI handle — a real char address). Optionally fill with initial data via fill Execute nemu_bind_all_imports Batch-bind host functions to ALL resolved import stubs in the GOT. Reads the GOT table (0x74000 range), finds Execute nemu_bind_host_fn Register a JavaScript host function at a specific guest address, overriding any existing stub. The function re Execute nemu_call_address Call a function at an arbitrary guest address (e.g. a native method registered via RegisterNatives). Uses AArc Execute nemu_call_jni_export Invoke an exported Execute nemu_call_symbol Invoke an exported function by name following AArch64 AAPCS (integer args in x0..x7, result in x0). Auto-detec Execute nemu_create_jni_handle Create a mock JNI object handle pre-populated with controlled data. Use BEFORE calling JNI functions to seed t Execute nemu_create_session Create an isolated ARM64 emulator session and return its sessionId. Each session owns its own CPU registers, g Execute nemu_gdbserver GDB Remote Serial Protocol (RSP) TCP server. Starts a real TCP server on host:port that GDB clients can connec Execute nemu_load_apk_library Extract a specific arm64-v8a .so from an APK by name and load it into a session in one step (no temp files). P Execute nemu_load_library Load an AArch64 ELF shared object (.so) from a filesystem path into a session, mapping its segments and resolv Execute nemu_load_library_chain Load a chain of dependent libraries into a session, resolving inter-library imports. Pass dependency .so paths Execute nemu_mem_map Map a memory region in guest address space. Use to extend the mapped area for output buffers or scratch data t Execute nemu_new_byte_array Wrap base64 bytes as a JNI jbyteArray handle to pass as an argument into call_jni_export (e.g. the plaintext a Execute nemu_patch_apply Apply multiple memory patches in a single call. Each patch is {address, dataBase64, writeProtect?}. Faster tha Execute nemu_prepare_tls Map the TPIDR_EL0 (thread-pointer) TLS block so its memory is accessible for pre-population via nemu_write_reg Execute nemu_relay Connect to a remote native-emulator session via IPC relay. Proxies nemu operations through a named pipe (Windo Execute nemu_session_load Load a JSON-serialised array of tool calls and execute them sequentially to set up a session. Each entry is {t Execute nemu_set_registers Set arbitrary CPU registers by index. Pass an object mapping register number to value (e.g. {0: 0x60000000, 10 Execute nemu_set_vtable_slot Override a specific vtable slot with a custom host function. The slot at vtableAddr + slotIndex8 is rewritten Execute nemu_trace Invoke an exported symbol while recording every instruction executed (pc, opcode, step), optionally snapshotti Execute nemu_vm_state_load Load VM state into guest memory. Takes ctx values and table values as hex strings and writes them at the speci Execute nemu_write_memory Write raw bytes into guest memory at a given address via base64 data. Use to update an input buffer between ca Execute nemu_write_regions Write multiple memory regions in a single call. Accepts an array of {address, dataBase64} objects. Essential f Execute nemu_xor_region XOR a region of emulated memory with a single-byte key. Returns the XOR result as base64. Use for quick decryp Execute net_raw_tcp_listen Listen on a local TCP port for one incoming connection. Execute net_raw_tcp_send Send raw TCP data to a remote host; accepts hex or text input. Execute net_raw_udp_listen Listen on a local UDP port for an incoming datagram. Execute net_raw_udp_send Send a raw UDP datagram and wait for a response. Execute network_disable Disable network request monitoring Execute network_enable Enable network request monitoring. Execute network_icmp_probe Run an ICMP echo probe. Execute network_intercept Manage network interception rules. Execute network_monitor Manage network request monitoring. Execute network_replay_request Replay a captured network request with optional changes. Execute network_rtt_measure Measure round-trip time to a target URL. Execute network_tls_fingerprint Compute TLS/HTTP fingerprints for bot detection. compute_tls/compute_http build fingerprints from user-supplie Execute network_traceroute Run an ICMP traceroute. Execute page_back Navigate back in browser history. Execute page_block_script Manage script blocking rules by URL pattern. Blocked scripts are prevented from loading/executing. Actions: ad Execute page_click Click a page element by CSS selector. Execute page_coverage_start Start JS+CSS code coverage collection on the active page. Coverage tracks which bytes of each loaded script/st Execute page_emulate_device Emulate a mobile device profile. Execute page_evaluate Execute JavaScript in page context. Execute page_forward Navigate forward in browser history. Execute page_handle_dialog Control how JavaScript dialogs (alert/confirm/prompt/beforeunload) are answered. By default installs a persist Execute page_hover Hover over an element by CSS selector. Execute page_inject_script Inject JavaScript to run on every page load. Execute page_navigate Navigate the page to a URL with wait and network options. Execute page_press_key Simulate a key press by name. Execute page_reload Reload the current page. Execute page_script_run Execute a named script from the Script Library with optional runtime params (__params__). Execute page_scroll Scroll to absolute or relative coordinates. Execute page_select Select option(s) in a <select> element. Execute page_set_viewport Set the browser viewport dimensions. Execute page_type Type text into an element. Execute page_wait_for_selector Wait for an element to appear. Execute payload_mutate Apply deterministic byte-level mutations to a hex payload. Execute payload_template_build Build a deterministic payload from field definitions. Execute performance_trace Start or stop a Chrome performance trace. Execute process_detect_hollowing Detect process hollowing (malware technique that unmaps original process image and injects malicious code). Co Execute process_launch_debug Launch an executable with remote debugging port enabled. Execute process_resume Resume a previously suspended process. Cross-platform: NtResumeProcess (Win32), SIGCONT (Linux), task_resume ( Execute process_suspend Suspend a process for forensic snapshotting. Cross-platform: NtSuspendProcess (Win32), SIGSTOP (Linux), task_s Execute profiler_cpu Start or stop CPU profiling. Execute proxy_add_rule Add an interception rule: forward, mock_response, redirect, or block. Execute proxy_start Start the local HTTP/HTTPS interception proxy with optional TLS. Execute proxy_stop Stop the proxy and release all active rules. Execute query_trace_sql Execute a read-only SQL query against a trace database. Execute raw_ip_packet_build Build a deterministic IPv4 or IPv6 packet. Execute reload_extensions Reload plugins and workflows from configured directories, and directly register extension tools visible in the Execute reverse_session Create, inspect, list, preview, or run an end-to-end reverse-engineering workflow session with artifact root, Execute rizin_bridge Send a command to a local Rizin/r2 analysis bridge. Execute route_tool One-stop tool router: accepts a natural language task description, returns recommended tools and next Execute run_extension_workflow Execute an extension workflow by workflowId with optional config and timeout overrides. Execute run_macro Execute a registered macro with sequence, parallel, branch, fallback, and retry orchestration. Execute service_worker_deliver_push Deliver a synthetic push message to a service worker via CDP ServiceWorker.deliverPushMessage. Requires an att Execute service_worker_dispatch_sync Dispatch a Background Sync event to a service worker via CDP ServiceWorker.dispatchSyncEvent. Requires an atta Execute sse_monitor_enable Enable SSE monitoring by injecting EventSource interceptor. Execute start_trace_recording Start recording debugger traces into a SQLite database for time-travel. Execute stealth_configure_jitter Configure CDP timing jitter. Execute stealth_inject Inject anti-detection scripts to reduce bot fingerprint exposure. Execute stealth_set_user_agent Set User-Agent and fingerprint. Execute stealth_verify Run anti-detection checks. Execute stop_trace_recording Stop trace recording and return the final session summary. Execute syscall_direct_invoke Direct NT syscall invocation guidance. Resolves SSN for a given NT function and returns a stub template with u Execute syscall_ebpf_attach Live eBPF syscall attach — spawns a bpftrace process, captures syscall events as structured JSON in real time, Execute syscall_ebpf_trace Trace syscalls on Linux with eBPF. Requires root or CAP_BPF. Execute syscall_resolve_ssn Resolve NT syscall service numbers (SSN) from on-disk ntdll.dll. Parses the export table to extract Zw → SSN m Execute syscall_stack_capture Correlate captured syscall events with real JS call stacks via debugger integration. Goes beyond static heuris Execute syscall_start_monitor Start syscall monitoring. Execute syscall_stop_monitor Stop syscall interception and release all captured events. Execute tab_workflow Cross-tab coordination. Execute tasks_cancel Request cancellation of a background task (MCP 2.0 Tasks protocol). Only tasks in the working state can be can Execute tcp_close Close an open TCP session. Execute tcp_open Open a TCP session. Execute tcp_write Write data to an open TCP session. Execute tls_cert_pin_bypass_frida Bypass certificate pinning via Frida injection (supports the target TLS library and HTTP client frameworks). Execute tls_close Close an open TLS session. Execute tls_decrypt_payload Decrypt a TLS payload using a provided key, nonce, and algorithm. Execute tls_keylog_enable Enable SSLKEYLOGFILE output for TLS library clients. Execute tls_open Open a TLS session. Execute trace_recording Start or stop trace recording into a SQLite database. Execute transform_workbench Run a reproducible binary transform workbench over base64 inputs: base64, hex, XOR, RC4, AES-CBC/ECB decrypt, Execute understand_code Run semantic code analysis for structure, behavior, and risks. Execute unidbg_call Call a JNI function in a running Unidbg emulator session. Execute unidbg_emulate Emulate a native function with Unidbg when available. Execute unidbg_launch Emulate a native shared library in Unidbg. Execute unidbg_trace Get execution trace from Unidbg session with configurable detail. Execute v8_deopt_trace Trace V8 deoptimization events during a capture window. Primary path uses CDP Tracing (v8 category, V8.Deoptim Execute v8_heap_sampling Collect a V8 allocation sampling profile via CDP HeapProfiler. Starts sampling for a capture window (default 5 Execute v8_turbofan_graph Collect and visualize V8 TurboFan IR (sea-of-nodes / Turboshaft graph). Two modes: (1) Provide JS source code Execute v8_turbofan_inspect Inspect JIT/TurboFan compilation state for functions in a script. Reports optimization tier (interpreted/magle Execute v8_type_profile Atomic primitive: start or stop V8 type profiling via CDP Profiler.startTypeProfile() / takeTypeProfile() / st Execute wasm_instrument_binary Real wasm-level binary instrumentation: disassembles via wasm2wat, inserts a call to an imported trace functio Execute wasm_instrument_block Real wasm-level basic-block instrumentation: disassembles via wasm2wat, inserts a call to an imported trace fu Execute wasm_instrument_trace Generate a JS instrumentation wrapper for a .wasm module. Execute wasm_offline_run Run an exported .wasm function. Execute wasm_optimize Optimize a .wasm binary for size or speed. Execute wasm_to_c Transpile .wasm bytecode to C source and header files. Execute watch Manage watch expressions for monitoring variable values during debugging.\n\nActions:\n- add: Add a watch expr Execute webcrack_unpack Run webcrack bundle unpacking and return extracted module graph. Execute webgpu_frame_timing Measure per-frame CPU and GPU cost over a rAF loop using GPU timestamp queries (device.limits.timestampPeriod Execute webgpu_shader_compile Compile WGSL shader and extract metadata (entry points, bindings, attributes). Validates shader code and detec Execute webgpu_timing_analysis GPU timing analysis for side-channel detection. Measures GPU command execution time variance to detect cache-b Execute websocket_open Open a WebSocket session. Execute websocket_send_frame Send a WebSocket frame. Execute widget_challenge_solve Solve a widget challenge with hook, manual, or configured external service. Execute workflow_conditional_step Evaluate a condition against the stepResults argument and execute one of two tool branches. Supports built-in Execute ws_monitor Enable or disable WebSocket frame capture. Execute ws_send_frame Send a frame through a live in-page WebSocket instance retained by ws_monitor(exposeInstances=true). Enables e
WRITE 70 tools
Write adb_file_push Push a local file to an Android device using normal ADB permissions. Write android_runtime_dump_session Create or inspect a managed Android runtime dump session from Frida/ADB dump artifacts, DEX files, and /proc/P Write asar_repack Pack a directory tree into an Electron ASAR archive (inverse of asar_extract). Walks the input directory and w Write blackbox_add Blackbox scripts (skip during debugging)\n\nUsage:\n- Skip third-party library c... Write blackbox_add_common Blackbox all common libraries (one-click)\n\nIncludes:\n- jquery, react, vue, an... Write browser_font_fingerprint Enumerate locally-installed fonts for fingerprint analysis. Primary path is the Local Font Access API (queryLo Write browser_jsdom_cookies Manage cookies on a JSDOM session. Isolated from the attached browser. Write captcha_config Configure CAPTCHA detection sensitivity and solver backend. Write checksum_apply Apply a deterministic 16-bit Internet checksum across a payload slice, optionally zeroing and writing the chec Write complete_task_handoff Mark a task handoff as completed. Write coordination_restore_snapshot Restore a saved page snapshot including IndexedDB data. Navigates to the captured URL, re-injects cookies, loc Write create_task_handoff Create a persisted task handoff for cross-tool coordination. Write cross_domain_evidence_export Export the shared cross-domain evidence graph as JSON. Write dart_symbolize Resolve obfuscated Dart identifiers using a developer-supplied Flutter --save-obfuscation-map JSON (flat, pair Write deactivate_tools Remove previously activated tools to free context. Write debugger_disassemble Disassemble V8 bytecode / instructions at the current paused location (or a given scriptId). Resolves the targ Write debugger_session Manage debugger sessions. Actions: save (persist current session to file), load (restore session from file/JSO Write dns_bulk_resolve Resolve many hostnames concurrently with per-host status. Write dns_resolve Resolve a hostname to DNS records using the system resolver or an optional DNS server. Write evidence_export Export the reverse evidence graph as JSON snapshot or Markdown report. Write export_hook_script Export generated hook templates as a complete, runnable Frida script. Write export_trace Export a trace database. format= Write grpc_export_capture Export captured gRPC / gRPC-Web calls to artifacts/captures as JSON or NDJSON. Write instrumentation_artifact Manage artifacts captured by instrumentation operations. Write instrumentation_session_export Export an instrumentation session snapshot to an artifacts JSON file. Write instrumentation_session_merge Merge two sessions into a new session: copies operations (with id remapping) and artifacts from both sources. Write memory_assemble Assemble x64 assembly instructions to machine code bytes (x64dbg inline assembler parity). Uses Keystone assem Write memory_audit_export Export the in-memory audit trail for memory operations as JSON. Write memory_bookmark Manage address bookmarks for a process. Actions: add (bookmark an address with optional label and color), remo Write memory_freeze_export Export all active freeze entries as structured JSON. Returns an array of freeze entries with freezeId, pid, ad Write memory_generate_signature Generate an update-resistant AOB (Array-of-Bytes) signature from bytes at a memory address. Detects relative o Write memory_patch_undo Undo a previous patch by restoring the original bytes. Write memory_pointer_map Save, load, or compare pointer maps for cross-instance filtering (Cheat Engine .PTR parity). save: serialize p Write memory_register_type Register a custom value type for memory scanning (Cheat Engine parity). Registered types can be used as valueT Write memory_reverse_mwt Reverse memory write trace — given a code address, find what data addresses the instruction accesses. Inverse Write memory_structure_export_c Export an inferred structure as a C-style struct definition, ReClass.NET XML, Rust [repr(C)], or C [StructLayo Write memory_type_define Override field types in an inferred structure. Actions: set (define a type at offset+size), list (show all ove Write memory_write_history Undo or redo the last memory write operation. Pass pid to scope the operation to a specific process — per-PID Write nemu_dump_got Dump the PLT trampoline → GOT → symbol mapping for an AArch64 ELF shared object. Scans .text for the 4-instruc Write nemu_mem_shadow Add a shadow memory overlay at a specific address. Reads from shadow take priority over underlying memory — us Write nemu_regs_restore Restore GPR registers from a previously-saved snapshot (created by nemu_regs_save). Partially restores: only r Write nemu_regs_save Save a named snapshot of current GPR registers (x0-x30, sp). Returns a snapshot id usable with nemu_regs_resto Write nemu_set_pac_key Configure the ARMv8.3 Pointer Authentication key set used by PACIA/PACIB/AUTIA/AUTIB/PACGA instructions in thi Write nemu_setup_java_field Register a mock Java field the emulated native code reads back via JNI (GetFieldID/GetStaticFieldID + Get<Type Write nemu_setup_java_mock Register a mock Java method for JNI callbacks. returnInt/returnString/returnBytes for single constant; returnM Write nemu_setup_java_mocks Batch-register multiple Java method mocks in one call. Each entry in the array has the same fields as nemu_set Write network_export_har Export captured network traffic as HAR. Write page_script_register Register a named reusable JS snippet in the Script Library. Execute with page_script_run. Write page_upload_files Upload one or more local files into an <input type= Write pcap_write Write a compact classic PCAP file from deterministic packet byte records. Write pcapng_write Write a PCAPNG (pcap-ng) capture file from one or more interfaces and deterministic packet byte records. Emits Write proto_export_schema Export a protocol pattern to a schema definition. format: proto (default, .proto-like text), ksy (Kaitai Struc Write proxy_export_ca Read the proxy CA certificate. Write proxy_setup_adb_device Configure an Android device to use the proxy. Write restore_page_snapshot Restore a saved page snapshot. Write save_page_snapshot Save current page state. Write script_replace_persist Persistently replace matching script responses. Write sourcemap_reconstruct_tree Reconstruct source files from a source map. When a vendor stripped sourcesContent, set inferMissing=true to em Write sse_export_capture Export captured SSE events to artifacts/captures as JSON or NDJSON. Write state_board CRUD operations on the cross-tool shared state board. TTL contract for set: omitting ttlSeconds defaults to 24 Write stealth_generate_fingerprint Generate a browser fingerprint. Write syscall_trace_export Export captured syscall events to portable NDJSON with optional time-range filtering and deduplication. Return Write tls_cert_pin_bypass Return a certificate pinning bypass strategy for the selected platform. Write tls_keylog_disable Disable SSLKEYLOGFILE capture and unset the environment variable. Write tls_write Write data to an open TLS session. Write update_task_handoff Update task handoff status or metadata without completing it. Write webrtc_export_capture Export messages captured by the WebRTC data-channel monitor to artifacts/captures as JSON or NDJSON. Write websocket_close Close an open WebSocket session. Write workflow_retry_policy Configure a global retry policy with exponential backoff for workflow steps. The stored policy is applied by r Write ws_export_capture Export captured WebSocket frames to artifacts/captures as JSON or NDJSON.
READ 348 tools
Read adb_apk_analyze Analyze an installed APK: package, permissions, activities, and security info. Read adb_apk_pull Pull an APK from a device to the local filesystem. Read adb_device_list List all connected Android devices and emulators. Read adb_file_pull Pull a file from an Android device using normal ADB permissions. Read adb_getprop Dump and parse Android system properties (getprop) into a structured map with a curated device fingerprint (mo Read adb_logcat_query Capture and filter Android logcat output in-process without shell grep pipelines. Read adb_package_summary Return structured Android package metadata: launcher, uid, versions, permissions, components, and native libra Read adb_proc_maps Read and parse /proc/PID/maps from a device, resolving PID from packageName when needed. Read adb_pull_native_libs Pull native shared libraries (.so) for an installed app from a device. Read adb_root_check Probe root indicators such as su, Magisk, test-keys, SELinux, and shell uid. Read adb_screenrecord Record a short MP4 screen capture through adb shell screenrecord and pull it locally. Read adb_screenshot Capture a PNG screenshot through adb exec-out screencap -p. Read adb_ui_dump Capture Android UI hierarchy via uiautomator dump. Runs uiautomator dump on-device, pulls the XML, and returns Read adb_webview_list List debuggable WebView targets connected via ADB. Read ai_suggest_exploits Use LLM to suggest exploit primitives and attack chains for a given vulnerability. Returns theoretical exploit Read analysis_ast_match Match AST nodes by type and optional property filter. Read analysis_data_flow Trace data flow through JavaScript: identify sources (user input, network, storage), sinks (XSS, eval, SQL inj Read analysis_decode_string_array Decode literal string-array access back to strings. Read analysis_security_scan Static security scan of JavaScript: detect hardcoded secrets (API keys, tokens), dangerous functions (eval, Fu Read antidebug_detect_protections Detect anti-debug protections in current page with bypass recommendations. Read apk_dex_intake Build a cohesive APK/DEX intake evidence packet: ZIP entries, manifest summary, DEX headers, native libraries, Read apk_manifest_dump Extract AndroidManifest.xml from an APK for quick inspection. Read apk_manifest_query Return a compact structured AndroidManifest summary: package, launcher activity, app class, SDKs, permissions, Read apk_native_libs_list List packaged native shared libraries (.so) inside an APK. Read apk_packer_detect Detect Android APK packers by matching Read apk_packer_list_signatures List the in-process signature table used by Read apk_signing_block_parse Read-only parser for the APK Signing Block (schemes v2/v3/v3.1/v4) plus key-rotation lineage detection and res Read apk_static_triage One-shot APK triage: ZIP metadata, manifest summary, native libs, asset hints, likely packers/protectors, and Read apktool_decode Decode an APK using apktool to inspect resources, manifest, and smali output. Read append_session_insight Record a persisted insight for the current session. Read asar_deobfuscate Scan every .js file inside an ASAR archive for obfuscation indicators (string-array arrays, webpack bundles, c Read asar_extract Extract and list files from an Electron ASAR package. Read asar_search Grep text patterns inside ASAR archive contents without extraction. Read ast_transform_beautify Pretty-print minified or obfuscated JavaScript: re-emit the parsed source with standard 2-space indentation an Read ast_transform_preview Preview lightweight AST-like transforms (string/regex based) and return before/after diff. Read binary_decode Decode binary payloads, transport encodings, and compressed blobs into hex, utf8, or json output. Read binary_detect_format Detect binary payload format and encoding signals. Read binary_encode Encode utf8/hex/json input into transport encodings or compressed base64 blobs. Read binary_entropy_analysis Compute entropy and byte frequency for a payload. Read binary_entropy_profile Compute Shannon entropy across fixed-size chunks of a binary file to locate encrypted / packed / compressed se Read binary_instrument_capabilities Report binary instrumentation backend availability. Read binary_key_extract Scan a binary for hardcoded key candidates (raw high-entropy, Base64, hex). Read-only — no decryption. Read binary_strings_extract Extract printable ASCII/UTF-16LE strings from a binary file with regex filtering. Read blackbox_list List script blackbox patterns. Read browse_extension_registry Browse the online extension registry for installable plugins and workflows. Read browser_cdp_performance_metrics Atomic primitive: fetch browser runtime metrics via CDP Performance.getMetrics() on the active page. Returns r Read browser_get_metrics Atomic primitive: collect page performance metrics via PerformanceMonitor — Web Vitals (FCP, LCP, CLS, TTFB), Read browser_jsdom_query Query a JSDOM session with a CSS selector. Read browser_jsdom_serialize Serialize a JSDOM session to HTML. Read browser_list_cdp_targets List CDP targets with optional type/URL/title filters. Read browser_list_tabs List open browser tabs with URLs and titles. Read browser_list_workers Enumerate Service Worker / Shared Worker / dedicated Web Worker targets via Target.getTargets. Use browser_wor Read browser_passkey_seed Seed a WebAuthn/Passkey credential into the browser for test automation. Read browser_resource_timing Atomic primitive: read Resource Timing API entries for the active page and decompose each resource into dns / Read browser_status Report browser status: running, tab count, version. Read browser_worker_scripts Attach a CDP session to a worker target and dump its parsed scripts (equivalent to get_all_scripts, but scoped Read call_graph_analyze Analyze runtime function call graph from in-page traces. Read camoufox_geolocation Get geolocation for a locale. Read canvas_dump_shaders Dump the linked shader programs (vertex + fragment source, uniforms) running on the target canvas. Uses engine Read canvas_engine_fingerprint Detect Canvas/WebGL game engines in the page. Read canvas_memory_invariants Assert runtime invariants about WebGL context lifetime, engine state consistency, and texture/program leaks. R Read canvas_pick_object_at_point Pick / hit-test the topmost object at a given screen coordinate using the engine Read canvas_scene_dump Extract the full scene tree / display list from a detected canvas engine. Read canvas_scene_search Search a previously-dumped scene tree (canvas_scene_dump output) for nodes by name regex and/or type. Pure-com Read captcha_detect Detect CAPTCHAs on the current page. Read captcha_solver_capabilities Report CAPTCHA solving mode availability. Read check_debug_port Check if a process is being debugged using NtQueryInformationProcess (ProcessDebugPort). Read collect_code Collect JavaScript from a target website with configurable strategy. Read console_get_exceptions Get captured uncaught exceptions from the page Read console_get_logs Retrieve captured console logs with type and time filters. Read console_monitor Toggle console log capture (log, warn, error, info, debug). Read coverage_report Report which tools have been called in the current runtime and which known tools remain uncalled. Read cross_domain_capabilities List all cross-domain capability categories and available workflows. Read cross_domain_evidence_query Query the shared evidence graph by URL, heap address, function, script, node type, metadata, or chain. Read cross_domain_evidence_stats Get node and edge statistics for the shared cross-domain evidence graph. Read cross_domain_health Report health status of cross-domain bridges and correlators. Read cross_domain_suggest_workflow Recommend a multi-domain workflow to achieve a specific analysis goal. Read cross_domain_synonym Map natural-language queries to tool recommendations using a lightweight synonym graph. Pure TS — no LLM. Usef Read crypto_compare Compare two crypto implementations against identical test vectors. Read dart_call_graph Build a best-effort static call graph from a Dart AOT snapshot: nodes are Code objects, edges are ObjectPool e Read dart_inspect_object_pool Dump an ObjectPool at a specific address, showing all entries with types and values. Pass a sessionId to reuse Read dart_list_functions List all Dart Code objects (compiled functions) from a loaded snapshot, with entry point address, size, and na Read dart_load_snapshot Load and parse a Dart AOT snapshot from libapp.so, extracting metadata and statistics (Code objects, ObjectPoo Read dart_object_pool_dump Read-only static dump of the Dart isolate ObjectPool in a libapp.so: classify each slot as smi/mint/double/str Read dart_pc_descriptors Parse PcDescriptors for one or all Dart functions in a loaded snapshot and resolve call targets by decoding AR Read dart_smi_scan Recover Dart Small Integer (Smi) constants from a libapp.so by reading aligned little-endian words and strippi Read dart_snapshot_header_parse Parse the Dart isolate snapshot header in a libapp.so: magic, kind, 32-byte hash, features, target arch. Read- Read dart_strings_extract Stream-extract ASCII/UTF-16LE strings from a Dart AOT libapp.so and classify them (urls, paths, classNames, pa Read dart_version_fingerprint Identify Flutter/Dart SDK release from a libapp.so by combining header parse with a built-in (and optionally u Read debugger_capture_hit Wait for the next debugger pause and capture call stack plus optional top-frame scope variables. Read debugger_get_paused_state Get current paused state and reason. Read describe_tool Get detailed information about a specific tool, including its input schema. Read detect_crypto Detect cryptographic algorithms and usage patterns in source code. Read detect_obfuscation Detect obfuscation techniques in JavaScript source. Read dex_scan_file Scan a binary/memory-dump file for DEX or CompactDex magic and optionally extract hits. Read diff_heap_snapshots Compare two heap snapshots from a trace. Read dns_cname_chain Trace the full CNAME chain for a hostname. Read dns_probe Run a DNS query and return structured status instead of throwing. Read dns_reverse Reverse DNS lookup — find hostnames for an IP address. Read electron_check_fuses Read Electron fuse states. Read electron_debug_status Check status of dual-CDP debug sessions launched by electron_launch_debug. Read electron_inspect_app Analyze Electron app structure: main/renderer entry, preload, IPC. Read electron_ipc_sniff Monitor Electron IPC messages. Read electron_scan_userdata Scan a directory for Electron JSON userdata files. Read electron_verify_integrity Verify Electron ASAR integrity: parse the ElectronAsarIntegrity JSON embedded in the main binary, locate each Read electron_verify_signature Inspect a packaged Electron binary Read enumerate_modules List all loaded modules (DLLs) in a process with their base addresses. Read evidence_chain Get full provenance chain from a node ID in specified direction. Read evidence_query Query reverse evidence graph by URL, function name, or script ID to find associated nodes. Read exploit_analyze_mitigations Detect binary security mitigations (NX/DEP, PIE/ASLR, stack canary, RELRO, FORTIFY_SOURCE, CFG). Returns boole Read exploit_cache_stats Get exploit-dev cache statistics including hit rate, memory usage, and entry count. Used for performance monit Read extension_info Read installed extension manifest details without importing plugin code. Read extension_list_installed List installed extensions from the local registry. Read extract_function_tree Extract a function and its dependency tree from collected scripts. Read fetch_stream_export_capture Export events captured by the fetch()-based stream monitor to artifacts/captures as JSON or NDJSON. Read fetch_stream_get_events Get events captured by the fetch()-based stream monitor (text/event-stream consumed via fetch). Set fullData=t Read flutter_packages_detect Detect third-party Dart Read framework_state_extract Extract React/Vue/Svelte/Solid component state and meta-framework info. Read frida_enumerate_functions Enumerate exported functions for a specific module in a Frida session. Read frida_enumerate_modules List loaded modules in an attached Frida session. Read frida_find_symbols Search for symbols matching a pattern in a Frida session. Read frida_list_sessions List all active Frida attach sessions with target info. Read frida_memory_read Read raw bytes from a Frida session via ptr(address).readByteArray. Returns hex; capped at 65536 bytes per cal Read get_all_scripts List all scripts loaded by the page with optional source. Read get_available_plugins List installed binary analysis plugins. Read get_cache_stats Get cache statistics: entries, sizes, hit rates, and cleanup recommendations. Read get_call_stack Get the current call stack. Read get_collection_stats Get collection, cache, and compression statistics. Read get_detailed_data Retrieve large data by detailId. Read get_object_properties Get properties of an object by objectId. Read get_offloaded_data Retrieve the original bytes of a field that was offloaded to disk (see the Read get_scope_variables_enhanced Enhanced scope variable inspection with deep object traversal. Read get_script_source Retrieve source code of a script by ID or URL pattern. Read get_task_context Read persisted task handoff context and session insights. Read get_token_budget_stats Get token budget usage stats, warnings, and optimization suggestions. Read ghidra_analyze Analyze a binary and return metadata. Read graphql_enum_schema Enumerate GraphQL fields from server suggestion errors with introspection fallback. Read graphql_extract_queries Extract GraphQL queries/mutations from captured network traces. Read graphql_introspect Run GraphQL introspection and optional Apollo Federation _service.sdl probing. Read grpc_frame_parse Split a captured gRPC / gRPC-Web body into its length-prefixed messages. Each message is 1 compressed-flag byt Read grpc_get_calls Get captured gRPC / gRPC-Web calls with parsed message summaries. Set fullMessages=true to include the parsed Read grpc_monitor Enable or disable live capture of gRPC / gRPC-Web calls. gRPC calls are detected by content-type application/g Read http2_frame_parse Decode a raw HTTP/2 frame (hex string) back into its header fields and type-specific payload (SETTINGS entries Read indexeddb_dump Export IndexedDB databases and records. Supports keyRange queries (IDBKeyRange.bound/lower/upper), indexName ( Read instrumentation_session_diff Diff two instrumentation session snapshots: operations added/removed/common (by id) plus artifact fingerprints Read jadx_decompile Decompile an APK class or method with JADX CLI. Read jadx_search_code Ripgrep-backed search over jadx output. Pass decompileDir for read-only search, or apkPath to auto-decompile t Read js_analyze_vm Analyze JSVMP/VM interpreter: dispatch type, handler table, opcode map. Read js_bundle_search Fetch a remote JS bundle and search it with named regex patterns, with caching and noise filtering. Read js_deobfuscate_jsvmp Deobfuscate JSVMP/VM-protected JavaScript: extract VM bytecode and restore original logic. Read js_heap_search Search JS heap for strings matching a pattern. Read list_extension_workflows List runtime-loaded extension workflows from plugins/ or workflows/ directories. Read list_extensions List all loaded plugins, workflows, and extension tools. Read list_macros List all available macros. Read list_page_snapshots List saved page snapshots. Read llm_suggest_names Use LLM to suggest meaningful names for obfuscated identifiers. Read maintenance_detect_gpu Detect GPU family from WebGL/WebGPU renderer strings. Classifies into NVIDIA, AMD, Intel, Apple, Mali, Adreno, Read memory_anticheat_detect Scan process imports for anti-debug/anti-cheat mechanisms: IsDebuggerPresent, NtQueryInformationProcess, timin Read memory_antidetection_check Pre-flight anti-detection security audit. READ-ONLY — no patches or modifications. Checks: (1) ETW/AMSI patch Read memory_aob_scan Array-of-Bytes scan with wildcard and operator support (CE 7.6 parity). Search for byte patterns like Read memory_check_protection Check memory protection flags at a specific address. If pid is omitted, the active browser renderer PID is aut Read memory_code_caves Find code caves (runs of 0x00 or 0xCC) in executable sections of loaded modules. Returns largest caves first. Read memory_dump Dump memory region as hex with ASCII column. Outputs a formatted hex dump similar to xxd. Read memory_dump_region Dump a process memory region to a binary file for offline analysis. If pid is omitted, the active browser rend Read memory_emulator_detect Detect if a target process is a known console emulator (ArtMoney parity). Supports: PCSX2, Dolphin, RPCS3, Yuz Read memory_find_references Find all references to an address in executable memory (x64dbg parity). Scans all executable regions for CALL Read memory_group_scan Search for multiple values at known offsets simultaneously. Read memory_guard_pages Find all memory regions with PAGE_GUARD protection in a process. Guard pages are often used as anti-tampering Read memory_handle_enum Enumerate all open handles in a target process via NtQuerySystemInformation. Returns handle value, object type Read memory_heap_anomalies Detect heap anomalies: heap spray patterns (many same-size blocks), possible use-after-free (non-zero free blo Read memory_heap_enumerate Enumerate all heaps and heap blocks in a process via Toolhelp32 snapshot. Returns heap list with block counts, Read memory_heap_stats Get detailed heap statistics with size distribution buckets (0-64B, 64B-1KB, 1-64KB, 64KB-1MB, >1MB), fragment Read memory_inline_hook_detect Detect hooks in process modules. scanMode Read memory_integrity_check Check executable memory regions against their corresponding on-disk PE files (.text sections) to detect modifi Read memory_list_regions List all memory regions in a process with protection flags. If pid is omitted, the active browser renderer PID Read memory_list_types List all registered custom scan types. Read memory_mono_assemblies List Mono assemblies loaded in the root domain of a Unity/Mono process. Returns assembly name, address, and im Read memory_mono_classes List Mono classes in a specific assembly from a Unity/Mono process. Reads the MonoImage type definition table Read memory_mono_detect Detect Mono or IL2CPP runtime in a target process. Returns runtime kind (mono/il2cpp), module name, pointer si Read memory_mono_fields Read field values from a Mono object at the given address. Resolves the class via vtable pointer, walks MonoCl Read memory_mono_methods Inspect method count for a Mono class in a Unity/Mono process. Full method name enumeration requires walking t Read memory_mono_objects Find live Mono objects of a specific class in the managed heap. Resolves class vtable, then scans writable hea Read memory_parse_dump Parse a Windows Minidump (.dmp) file and extract forensic information: loaded modules (base/size/name/timestam Read memory_pe_headers Parse PE headers (DOS, NT, File, Optional) from a module base address in process memory. Returns machine type, Read memory_pe_imports_exports Parse import and/or export tables from a PE module in process memory. Returns DLL names, function names, ordin Read memory_pointer_scan Find pointers to a target address. Read memory_read Read memory from a process at a specific address. Requires elevated privileges. If pid is omitted, the active Read memory_read_typed Read process memory as typed numeric values with explicit endianness. Decodes consecutive values starting at a Read memory_region_compare Compare two memory regions byte-by-byte and return a diff summary. Equivalent to Cheat Engine Read memory_region_enumerate Enumerate memory regions in a target process. Cross-platform: Windows (VirtualQueryEx), macOS (mach_vm_region) Read memory_rtti_info Parse MSVC RTTI (Run-Time Type Information) at an object address. Reads vtable pointer, follows the Complete O Read memory_scan_filtered Refine a previous memory scan with filtered addresses. If pid is omitted, the active browser renderer PID is a Read memory_search_string Search process memory for strings matching a pattern. Wraps memory_first_scan with valueType=string for conven Read memory_structure_analyze Analyze memory at an address to infer data structure layout. Read memory_structure_compare Compare struct instances to identify differing vs constant fields. Two modes: (1) Pairwise—compare address1 vs Read memory_vtable_parse Parse a vtable to enumerate virtual function pointers and resolve them to module+offset. Also attempts RTTI pa Read miniapp_pkg_analyze Analyze an unpacked miniapp package. Read miniapp_pkg_scan Scan local directories for miniapp package files. Read mojo_decode_message Decode a Mojo IPC hex payload into a structured field map. Read mojo_ipc_capabilities Report Mojo IPC monitoring availability. Read mojo_list_interfaces List discovered Mojo IPC interfaces and their pending message counts. Read mojo_messages_get Retrieve captured Mojo IPC messages from the active monitoring session. Read mojo_messages_summarize Aggregate the captured Mojo IPC buffer (non-destructive) into interface/method/direction breakdowns, top-N lis Read native_bridge_status Check native bridge backend health. Read native_symbol_sync Export native symbols to connected analysis backends. Supports json/csv/idc/sqlite output; an optional sinceHa Read nemu_bytecode_decode Decode a u32 LiteVM bytecode word into its opcode fields: group (G0-G7), sub-opcode, a1 register index, fl fie Read nemu_bytecode_scan Scan a guest memory region and decode all valid LiteVM bytecode words. Reads Read nemu_capabilities Report native-emulator backend availability, supported features, and explicit ISA/SIMD gaps. Unsupported opcod Read nemu_data_dump Read a guest memory region and format it as a structured table of u32 or u64 values. Each row shows offset, he Read nemu_dlsym_diag Read the dlsym resolution log from the current session. Tracks every symbol lookup the emulated code requested Read nemu_dump_frame Read and decode a CreateLitevm frame structure from guest memory. Parses the 256-byte frame fields: chain poin Read nemu_extract_apk_libs List the loadable arm64-v8a native libraries (.so) packaged inside an APK, with their byte sizes. Use nemu_loa Read nemu_get_jni_stub Get the guest stub address for a JNI table index. Pass a specific Read nemu_inspect_imports Inspect an AArch64 ELF .so before emulation and list imported symbols from dynamic relocations, including GOT Read nemu_jni_diag Read the JNI diagnostic log for a session. Tracks every JNI function call (FindClass, GetMethodID, CallIntMeth Read nemu_jni_handles List all JNI object handles allocated in a session, with their kind and summary. Handles are opaque IDs (jclas Read nemu_list_sessions List active emulator sessions with their creation and last-use timestamps. Read nemu_list_symbols List the exported function symbols of the loaded library — the names callable via call_symbol / call_jni_expor Read nemu_mem_inspect Single convergence entry point for the guest-memory inspection family — one tool, five Read nemu_pointer_chain Walk a chain of pointers in guest memory. Starting from Read nemu_read_byte_array Resolve a jbyteArray handle (e.g. a native call Read nemu_read_memory Read raw bytes from guest memory at a given address. Returns a bounded preview by default; set includeDataBase Read nemu_scan_memory Scan emulated memory for a byte pattern (like Volatility). Searches a guest address range for an exact byte ma Read nemu_session_info Inspect one emulator session without executing native code. Returns timestamps, exported symbols, unresolved i Read nemu_vm_state_compare Compare native VM state (read from guest memory) against an expected state (e.g. Python LiteVM dump). For each Read nemu_vm_state_dump Dump LiteVM state from guest memory at specified base addresses. Reads ctx (32×64-bit), table (32×64-bit), and Read network_bot_detect_analyze Analyze captured requests for bot-detection signals. Optionally supply a JA3/JA4 TLS fingerprint (from network Read network_extract_auth Extract authentication data from captured network requests. Read network_get_requests Get captured network requests. Read network_get_response_body Get the response body for a captured request. Read network_get_stats Get network statistics. Read network_get_status Get network monitoring status. Read network_http2_fingerprint Compute an Akamai-style HTTP/2 fingerprint from one or more captured HTTP/2 frames (the client connection pref Read network_latency_stats Measure repeated latency and compute percentile stats. Read page_coverage_stop Stop coverage collection and return per-script JS+CSS coverage results. Includes total bytes, used bytes, and Read page_list_frames List page frames for frame targeting. Read page_screenshot Capture a page or element screenshot. Read page_storage_info Query navigator.storage.estimate() for {usage, quota} and navigator.storage.persisted() to inspect the origin Read pcap_read Read a classic PCAP file and return compact deterministic packet summaries. PCAPNG is intentionally not suppor Read pcapng_read Read a PCAPNG (pcap-ng) capture file and return structured Section/Interface/Packet blocks. Supports Section H Read performance_get_metrics Get page performance metrics. Read platform_capabilities Report platform tool backend availability. Read process_check_debug_port Check if a process has a debug port enabled for CDP attachment. Read process_detect_apc Detect APC (Asynchronous Procedure Call) injection in a process. Enumerates threads, probes each thread APC qu Read process_enum_handles Enumerate open handles for a process using NtQuerySystemInformation. Resolves handle type and object name, dec Read process_enum_threads Enumerate all threads in a process. Returns thread IDs, with optional per-thread context and diagnostics. Cros Read process_find Search for processes by name pattern. Returns a list of matching processes with PID, name, path, and window in Read process_get Get detailed information about a specific process by PID, including command line, parent PID, and debug port s Read process_hollowing_scan Pure-TS static hollowing indicator scan. Analyses /proc/pid/maps (RWX regions), /proc/pid/exe (deleted backing Read process_kill Terminate a process by PID. Requires appropriate privileges. Read process_list List all running processes. This is an alias for process_find with an empty pattern. Read process_windows Get all window handles for a process. Read proto_auto_detect Auto-detect a protocol pattern from one or more hex payload samples. Read proto_define_pattern Define a protocol pattern with delimiter, byte order, and field layout. Read proto_dissect_dns Dissect a raw DNS payload (RFC 1035 + EDNS(0)) into header flags, questions, answers, authorities, and additio Read proto_dissect_http Dissect a raw HTTP/1.x request or response payload (RFC 7230) into the start line, headers, and body. Unwinds Read proto_fingerprint Identify protocol type from hex payload samples. Read proto_infer_fields Infer likely protocol fields from repeated hex payload samples. Read proto_infer_state_machine Infer a protocol state machine from captured message sequences. Read proto_visualize_state Generate a Mermaid state diagram from a protocol state machine definition. Read protobuf_decode_raw Decode protobuf bytes. Raw wire-format walk by default; schema mode returns ProtoJSON, expands valid google.pr Read proxy_get_requests Read captured proxy request/response metadata, body previews, and timing. Read proxy_list_rules List active proxy interception rules tracked by this handler. Read proxy_status Report proxy status, listen port, and CA certificate path. Read search_in_scripts Search collected scripts by keyword or regex pattern. Read seek_to_timestamp Reconstruct trace state at a specific timestamp. Read session_progress_coverage Query the session progress ledger: per-kind entry counts plus the matching entries sorted newest-first (by fir Read session_progress_record Record a piece of reverse-engineering progress evidence for the current session (a hooked process, a hook poin Read skia_correlate_objects Correlate requested Skia node identifiers with the extracted scene tree. Read skia_detect_renderer Detect the active Skia renderer backend from the current page context. Read skia_extract_scene Extract a lightweight Skia scene tree from the selected canvas. Read smart_cache_cleanup Evict LRU and stale entries while preserving hot data. Read snapshot_create Create a shadow-git snapshot of a scan-artifact directory (artifacts, HAR, screenshots, debugger-sessions, ... Read snapshot_list List shadow-git snapshots recorded for a directory, newest first. Read sourcemap_coverage Summarize mapped and unmapped source coverage. Read sourcemap_diff Compare two source map revisions: which sources were added/removed, per-source mapping segment deltas, and gen Read sourcemap_discover Discover source maps on the current page. Read sourcemap_fetch_and_parse Fetch a source map from URL and parse to original sources. Read sourcemap_lookup Resolve generated code position to original source (default), or — when originalSource is supplied — resolve o Read sourcemap_parse_v4 Parse source map with ECMA-426 v4 scope/debug-id support; falls back to v3. Read sse_get_events Get captured SSE events with filters and pagination. Read state_board_io Serialize state board to JSON or restore from a previous export. Read state_board_watch Watch state board keys for changes with configurable polling. Read summarize_trace Generate a compact summary of a trace database. Read syscall_capture_events Capture syscall events from the active or last monitoring session. Read syscall_correlate_js Correlate captured syscalls with likely JavaScript functions. Read syscall_filter Filter captured syscall events by name, PID, or return value. Read syscall_get_stats Get syscall monitoring statistics. Read syscall_origin_map Build a unified syscall→JS origin map by integrating live CDP call stacks (syscall_stack_capture) with static Read syscall_pattern_detect Scan captured syscall events for behavioral patterns relevant to reverse engineering: anti-debug probes (ptrac Read syscall_trace_compare Diff two syscall trace snapshots to find appeared/disappeared syscalls and frequency changes. Useful for under Read tasks_get Get the current state of a background task (MCP 2.0 Tasks protocol). Returns status (working/completed/failed/ Read tasks_list List recent background tasks tracked by the server (MCP 2.0 Tasks protocol). Expired tasks are pruned automati Read tasks_result Fetch the payload/result of a background task (MCP 2.0 Tasks protocol). Optionally waits (polls) up to waitMs Read tcp_read_until Read from an open TCP session until a delimiter or byte limit is reached. Read tls_cipher_suites List TLS cipher suites with IANA id, protocol, key-exchange / authentication / encryption / MAC split, and AEA Read tls_keylog_lookup_secret Look up a TLS secret by client random hex from the parsed keylog. Read tls_keylog_parse Parse an SSLKEYLOGFILE and summarize available key material. Read tls_keylog_summarize Summarize an SSLKEYLOGFILE: per-label distribution, secret-type classification (TLS 1.2 master-secret vs TLS 1 Read tls_parse_certificate Parse a TLS Certificate message from raw hex and extract X.509 details (subject/issuer/SAN/validity/keyUsage), Read tls_parse_handshake Parse TLS handshake metadata from raw hex. For payload decryption, use tls_decrypt_payload with explicit keyHe Read tls_probe_endpoint Probe a TLS endpoint and report handshake and certificate details. Read tls_read_until Read from an open TLS session until a delimiter or byte limit is reached. Read trace_get_network_flow Get a recorded request-scoped network flow from a trace. Read trace_get_samples Query recorded CPU profile samples. mode= Read v8_allocation_track Track live V8 allocations via CDP HeapProfiler object tracking. Enables the HeapProfiler, calls startTrackingH Read v8_bytecode_decompile Decompile or extract strings from V8 bytecode files. Read v8_bytecode_extract Extract V8 bytecode for a script by scriptId, with source fallback. Read v8_function_retained Find all heap objects retained by functions matching a name pattern. Walks the dominator tree to find objects Read v8_heap_diff Compare two heap snapshots to find allocation changes. Read v8_heap_find_leaks Find suspected memory leaks in a heap snapshot. Returns leak candidates sorted by confidence, including detach Read v8_heap_retainers Trace retainer chains from suspect leak objects back to GC roots. For each nodeId, walks the immediate-dominat Read v8_heap_snapshot_analyze Analyze a heap snapshot: class histogram (object count/sizes by constructor), statistics (total objects, detac Read v8_heap_snapshot_capture Capture a V8 heap snapshot for offline analysis. The snapshot is persisted to artifacts/heap-snapshots/ (data Read v8_heap_snapshot_export Export a heap snapshot as a complete .heapsnapshot JSON file under artifacts/heap-snapshots/, loadable by the Read v8_heap_snapshot_list List V8 heap snapshots — both in-memory (current session) and persisted to artifacts/heap-snapshots/ (survive Read v8_heap_stats Report V8 heap statistics: used, total, external. Read v8_object_compare Compare heap objects by shallow/retained size, class name, and property count. Same-snapshot mode (objectIds o Read v8_object_inspect Inspect a live JS object by objectId with property enumeration. Read v8_version_detect Detect V8 engine version, flags, and runtime capabilities. Read v8_wasm_inspect Inspect WebAssembly modules and garbage-collected WASM objects in the page. Discovers .wasm script resources v Read v8_weakrefs_inspect Enumerate WeakRef and FinalizationRegistry instances in the page via Runtime.evaluate. Inspects registered fin Read wasm_capabilities Report WASM tool availability. Read wasm_decompile Decompile .wasm bytecode to readable pseudo-code with type info. Read wasm_detect_obfuscation Detect WASM obfuscation: opaque predicates, control-flow flattening, bogus ops. Read wasm_diff Patch-diff two .wasm binaries (original vs. patched) for vulnerability research: disassembles both via wasm2wa Read wasm_disassemble Disassemble a .wasm binary to WAT text format. Read wasm_dump Dump a captured WebAssembly module from the current page. Read wasm_inspect Pure-TS wasm binary structural inspector (no wabt dependency). Parses the module surface — types, imports, fun Read wasm_inspect_sections Parse .wasm section headers: imports, exports, memory, tables, code. Read wasm_memory_inspect Inspect exported WebAssembly.Memory from the current page. Pages often load multiple WASM modules (crypto/DRM/ Read wasm_string_extract Extract printable strings from a .wasm binary, grouped by section, with name-section function-name recovery an Read wasm_vmp_trace Read captured WASM VMP import-call traces from the current page. Read webgpu_adapter_info Get WebGPU adapter information (vendor, architecture, device). Used for fingerprinting GPU capabilities and de Read webgpu_capture_commands Capture GPU command queue submissions (render passes, compute dispatches). Used for analyzing GPU workload and Read webgpu_error_capture Capture WebGPU validation/out-of-memory/internal errors the target app swallows (via device uncapturederror), Read webgpu_memory_layout Analyze GPU memory allocations and buffer usage. Identifies memory layout patterns that may be vulnerable to s Read webgpu_pipeline_dump Enumerate active render/compute pipelines, bind-group layouts, and render-pass descriptors by hooking GPUDevic Read webgpu_shader_disassemble Parse WGSL or SPIR-V shader into AST and generate human-readable disassembly. Used for reverse engineering sha Read webgpu_shader_source_capture Capture WGSL shader sources a running app compiles via GPUDevice.createShaderModule — the only artifact reveal Read webpack_enumerate Enumerate webpack modules in current page and search for keywords. Read webrtc_get_events Get messages captured by the WebRTC data-channel monitor. Set fullData=true to include full message data. Filt Read webrtc_monitor Enable or disable capture of WebRTC data-channel traffic. Wraps RTCPeerConnection in-page (no CDP coverage for Read websocket_read_frame Read the next queued WebSocket frame from an open session. Read workflow_run_inspect Inspect the global workflow run store: list recent run_extension_workflow / run_macro runs, get a run entry by Read workflow_suggest Suggest the next extension workflow to run from the chainsWith / prerequisites chain metadata declared by load Read ws_get_connections Get tracked WebSocket connections, frame counts, and timing metadata. Read ws_get_frames Get captured WebSocket frames with pagination and payload filter.

Related servers

Other MCP servers with similar tools — same risk classification, starter policies for each.

Questions about Jshookmcp

Can an AI agent delete data through the Jshook MCP server? +

Yes. The Jshookmcp server exposes 29 destructive tools including adb_uninstall, cleanup_artifacts, clear_all_caches. These permanently remove resources with no undo. PolicyLayer blocks destructive tools by default so they never reach the upstream server.

How do I prevent bulk modifications through Jshookmcp? +

The Jshookmcp server has 70 write tools including adb_file_push, android_runtime_dump_session, asar_repack. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach Jshookmcp.

How many tools does the Jshook MCP server expose? +

736 tools across 4 categories: Destructive, Execute, Read, Write. 348 are read-only. 388 can modify, create, or delete data.

How do I enforce a policy on Jshookmcp? +

Register the Jshook MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Enforce policy on every Jshookmcp tool call.

Deterministic rules across all 736 Jshookmcp tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Instant setup, no code required.

736 Jshookmcp tools catalogued and risk-classified — across an index of 46,500+ MCP servers.

// WHERE THIS COMES FROM

These policies come from Jshook's registry record.

The record behind this page: verified identity, auth posture, risk grade, every tool classified, recommended policy — re-checked continuously.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.