High-risk tools in Jshookmcp
289 of the 736 tools in Jshookmcp are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
activate_toolsExecuteDynamically register specific tools by name, regardless of current base tier.
-
adb_app_cold_start_traceExecuteHigh-level Android startup trace: force-stop, clear logcat, start activity with -W, wait, collect PID-filtered logs, and parse launch/Looper timing.
-
adb_dumpsysExecuteRun adb shell dumpsys for a service and return parsed structured output. Supports key-value extraction, array parsing, and section detection. Common services: package, activity,...
-
adb_input_keyeventExecuteSend an Android keyevent name or numeric key code through adb shell input.
-
adb_input_swipeExecuteSend a touchscreen swipe event through adb shell input.
-
adb_input_tapExecuteSend a touchscreen tap event through adb shell input.
-
adb_input_textExecuteSend text through adb shell input text with Android-safe whitespace encoding.
-
adb_installExecuteInstall one APK or a split-APK set onto a device with parsed success output.
-
adb_port_forwardExecuteManage ADB forward/reverse port mappings for device-host bridge workflows.
-
adb_shellExecuteExecute an ADB shell command on a specific device.
-
adb_webview_attachExecuteAttach to a WebView via ADB; returns WebSocket debugger URL for CDP.
-
ai_hookExecuteManage AI hooks. Actions: inject (inject code into page), get_data (retrieve captured hook data), list (all active hooks), clear (remove hook data by id or all), toggle (enable/...
-
analysis_deflat_control_flowExecuteFlatten switch-dispatch control flow back to straight-line code.
-
antidebug_bypassExecuteBypass one or more anti-debug protection types. Specify types to apply; omit or use [
-
api_probe_batchExecuteBatch-probe API endpoints in browser context with auto token injection and HTML skip.
-
apk_signExecuteSign an APK with apksigner using a caller-supplied keystore. Pairs with apktool_build for a full repack-and-sign workflow.
-
apktool_buildExecuteRebuild an APK from a decoded apktool source directory (closes the patch-and-repack loop with apk_sign).
-
arp_buildExecuteBuild a deterministic ARP payload for Ethernet/IPv4.
-
ast_transform_applyExecuteApply transforms to input code or a live page scriptId.
-
ast_transform_chainExecuteCreate and store an in-memory transform chain.
-
binary_ninja_bridgeExecuteSend a command to a local Binary Ninja analysis bridge.
-
breakpointExecuteManage breakpoints: code (line/script), function-name, XHR (URL pattern), event listener, event category, and exception breakpoints.\n\nActions:\n- set: Create a breakpoint. Typ...
-
browser_attachExecuteConnect to a running browser.
-
browser_attach_cdp_targetExecuteAttach to a CDP target by targetId.
-
browser_closeExecuteClose the browser and release all resources.
-
browser_codegen_startExecuteStart recording browser actions as replayable steps.
-
browser_codegen_stopExecuteStop recording browser actions and return cleaned replay steps.
-
browser_cpu_profile_startExecuteAtomic primitive: begin CDP CPU profiling on the active page (Profiler.start). Pair with browser_cpu_profile_stop to save the .cpuprofile. Set samplingInterval to 30-100 µs for ...
-
browser_cpu_profile_stopExecuteAtomic primitive: stop CDP CPU profiling, rank hot functions by sample count, and persist the raw profile to artifacts/profiles/ (or a custom path). The hot function list is der...
-
browser_detach_cdp_targetExecuteDetach the current CDP target session.
-
browser_evaluate_cdp_targetExecuteEvaluate JS in the attached CDP target.
-
browser_jsdom_executeExecuteEvaluate JS inside a JSDOM session. Requires explicit authorization — arbitrary code execution.
-
browser_jsdom_parseExecuteParse HTML into an in-memory JSDOM session. No browser needed.
-
browser_launchExecuteLaunch Chromium/Camoufox or connect to a running browser.
-
browser_performance_observerExecuteAtomic primitive: subscribe to PerformanceObserver entry types in the active page and return both buffered and live entries observed during a collection window. Entry types are ...
-
browser_select_tabExecuteSwitch active tab by index, URL pattern, or title pattern.
-
browser_trace_startExecuteAtomic primitive: begin a Chrome performance trace on the active page via page.tracing.start(). Pair with browser_trace_stop to save the trace to disk. Use a sensible categories...
-
browser_trace_stopExecuteAtomic primitive: stop the Chrome performance trace started by browser_trace_start and persist it to artifacts/traces/ (or to a custom path). Returns event count, file size, and...
-
call_toolExecuteExecute an already-active tool by name.
-
camoufox_serverExecuteStart, close, or check status of a Camoufox anti-detect server.
-
canvas_inject_draw_hookExecuteIntercept Canvas 2D (drawImage/fillText/strokeText) and WebGL (drawArrays/drawElements) draw calls into a ring buffer on the page. Actions: install (wrap prototypes), read (dump...
-
canvas_trace_click_handlerExecuteTrace a click event from DOM to JS call stack.
-
captcha_vision_solveExecuteSolve a CAPTCHA with manual flow or a configured external service.
-
captcha_waitExecuteBlock until the user manually solves the CAPTCHA.
-
console_buffersExecuteManage injected interceptor state.
-
console_executeExecuteEvaluate a JS expression in the browser console context.
-
console_injectExecuteInject an in-page script, XHR, fetch, or function monitor.
-
console_inject_fetch_interceptorExecuteInject a fetch interceptor.
-
console_inject_xhr_interceptorExecuteInject an XMLHttpRequest interceptor.
-
cross_domain_correlate_allExecuteRun the built-in skia, mojo, syscall, and binary correlators and merge the results into the shared evidence graph.
-
crypto_extract_standaloneExecuteExtract crypto/sign/encrypt function from current page and generate standalone runnable code.
-
crypto_test_harnessExecuteRun extracted crypto code in worker_threads + vm sandbox and return deterministic test results.
-
dart_call_functionExecuteExecute a Dart function in the ARM64 emulator by address or name, with simplified runtime (mock built-ins, tagged pointers). Pass a sessionId to reuse the cached snapshot; the e...
-
dart_create_sessionExecuteParse a Dart AOT snapshot once and cache it under a sessionId, so subsequent dart_load_snapshot / dart_list_functions / dart_call_graph / dart_inspect_object_pool / dart_call_fu...
-
dart_trace_executionExecuteTrace Dart function execution step-by-step, emitting each instruction with register state (PC, x0-x30, PP, THR). Pass a sessionId to reuse the cached snapshot.
-
debugger_evaluateExecuteEvaluate a JavaScript expression. context=
-
debugger_lifecycleExecuteEnable or disable the CDP debugger session.
-
debugger_pauseExecutePause execution at the next statement.
-
debugger_resumeExecuteResume execution.
-
debugger_run_to_locationExecuteRun execution until a source location by setting a temporary code breakpoint, resuming, waiting for pause, and removing the breakpoint.
-
debugger_stepExecuteStep execution: into (enter next call), over (skip next call), out (exit current function).
-
debugger_wait_for_pausedExecuteWait for debugger pause after setting breakpoints.
-
deobfuscateExecuteRun webcrack-powered JavaScript deobfuscation with bundle unpacking.
-
doctor_environmentExecuteRun environment doctor: dependencies, bridges, platform limits.
-
electron_attachExecuteAttach to an Electron CDP port and optionally evaluate in a matching page.
-
electron_launch_debugExecuteLaunch Electron with main and renderer CDP ports.
-
electron_patch_fusesExecutePatch Electron fuse states.
-
ethernet_frame_buildExecuteBuild a deterministic Ethernet II frame from source/destination MAC addresses, EtherType, and payload bytes.
-
execute_sandbox_scriptExecuteExecute JavaScript in an isolated sandbox.
-
exploit_build_format_stringExecuteGenerate format string exploit payload for arbitrary write. Uses %hn (2-byte) writes for reliability. Returns hex payload and reliability assessment.
-
exploit_build_heap_sprayExecuteGenerate heap spray payload for predictable heap layout. Supports V8 (ArrayBuffer), IE (BSTR), and generic (ArrayBuffer) spray targets. Returns spray code, allocation count, and...
-
exploit_build_jop_chainExecuteBuild a JOP (Jump-Oriented Programming) chain from binary gadgets.
-
exploit_build_ret2dlresolveExecuteBuild a ret2dlresolve payload that forges ELF dynamic-linker structures to resolve
-
exploit_build_rop_chainExecuteConstruct a ROP chain for a specified goal (execve, write_memory, call_function). Automatically searches for required gadgets and chains them. Returns hex chain and gadget list....
-
exploit_build_stack_pivotExecuteFind and assemble stack pivot gadgets from a binary. Stack pivots redirect the stack pointer (ESP/RSP) to a controlled buffer, enabling ROP chains when limited stack space is av...
-
exploit_cache_configureExecuteUpdate exploit-dev cache configuration (TTLs, memory limits, enable/disable). Changes take effect immediately.
-
exploit_calculate_offsetsExecuteCalculate buffer overflow offset from crash value and De Bruijn pattern. Used to determine exact EIP/RIP overwrite offset.
-
exploit_discover_one_gadgetExecuteDiscover one-gadget (single-address shell-spawning) offsets for common libc versions.
-
exploit_encode_shellcodeExecuteEncode shellcode to avoid bad characters or detection. Supports alphanumeric, unicode, XOR, and fnstenv encodings. Returns encoded shellcode and decoder stub. User must provide ...
-
exploit_find_gadgetsExecuteSearch for ROP/JOP/COP/COOP gadgets in a binary file. Returns addresses, instructions, and bytes for each gadget. Supports filtering by regex pattern and gadget type. User must ...
-
exploit_find_jmp_espExecuteFind
-
exploit_generate_egghunterExecuteGenerate egghunter shellcode for constrained buffer sizes. An egghunter searches process memory for a 4-byte
-
exploit_generate_patternExecuteGenerate De Bruijn sequence for offset finding. Every 4-byte substring is unique, allowing precise offset calculation from crash dumps.
-
exploit_generate_pwntoolsExecuteGenerate a pwntools-compatible Python exploit script (exploit.py).
-
exploit_solve_constraintsExecuteSolve a system of constraints using the Z3 SMT solver.
-
exploit_verify_rop_chainExecuteVerify a user-supplied ROP chain against an exploit goal using Z3.
-
extension_execute_in_contextExecuteLoad an extension and execute a named exported context function.
-
extension_installExecuteInstall/register an extension from a manifest, local package directory, local module file, or remote module URL.
-
extension_reloadExecuteReload an installed extension by unloading and loading it again.
-
fetch_stream_monitorExecuteEnable or disable capture of fetch()-based streams. Wraps window.fetch and, for responses with content-type text/event-stream, clones the body and parses the SSE frame stream in...
-
frida_attachExecuteAttach Frida to a local target and open a session.
-
frida_attach_interceptorExecuteGenerate a real Frida Interceptor.attach block for a symbol and optionally install it in a session.
-
frida_detachExecuteDetach from a Frida session and clean up resources.
-
frida_dex_dumpExecuteRun frida-dexdump as a high-level Android DEX dump helper by package/process name or PID.
-
frida_generate_scriptExecuteGenerate a Frida interceptor or hook script from built-in templates.
-
frida_memory_scanExecuteScan process memory for a byte pattern via Frida Memory.scanSync. Searches a named module, an explicit address range, or all readable ranges by default. Pass async:true to scan ...
-
frida_resumeExecuteResume a target previously spawned for early Frida instrumentation.
-
frida_run_scriptExecuteExecute a Frida JavaScript snippet inside an attached Frida session. Pass async:true to run in a background task (MCP 2.0 Tasks) and poll with tasks_get/tasks_result — useful fo...
-
frida_spawnExecuteSpawn a target through Frida for early instrumentation before normal execution.
-
generate_hooksExecuteGenerate a Frida interceptor script for a list of symbols.
-
ghidra_bridgeExecuteSend a command to a Ghidra headless analysis bridge.
-
graphql_replayExecuteReplay a GraphQL operation with optional variables, batch array, or Apollo persisted-query (APQ) extensions.
-
graphql_subscribeExecuteOpen a GraphQL subscription WebSocket, perform the graphql-transport-ws (or legacy graphql-ws) handshake, send a subscribe frame, and collect frames for collectMs. Runs in-page ...
-
grpc_frame_buildExecuteEncode one or more messages into a gRPC / gRPC-Web length-prefixed body. Inverse of grpc_frame_parse — for constructing test or replay bodies. Each message takes payloadHex plus...
-
hook_presetExecuteInstall a pre-built JavaScript hook from 20+ built-in presets (eval, atob/btoa, Proxy, Reflect, Object.defineProperty, etc.), or provide customTemplate/customTemplates to instal...
-
http_plain_requestExecuteSend a raw HTTP request over plain TCP.
-
http_request_buildExecuteBuild a raw HTTP/1.x request payload.
-
http2_frame_buildExecuteBuild a raw HTTP/2 frame.
-
http2_probeExecuteProbe an HTTP/2 endpoint.
-
human_mouseExecuteMove mouse along a Bezier curve with jitter.
-
human_scrollExecuteScroll with randomized speed and pauses to mimic human behavior.
-
human_typingExecuteType text with human-like speed and occasional typos.
-
icmp_echo_buildExecuteBuild a deterministic ICMPv4 echo request or reply payload with an automatically computed checksum.
-
ida_bridgeExecuteSend a command to an IDA Pro plugin bridge.
-
inject_dllExecuteInject a DLL into a target process. Requires elevated privileges. Target process and payload are validated before injection.
-
inject_shellcodeExecuteAllocate and execute raw shellcode in a target process. Requires elevated privileges. Target process and payload are validated before injection.
-
install_extensionExecuteInstall an extension from the remote registry.
-
instrumentation_hook_presetExecuteApply hook presets inside an instrumentation session.
-
instrumentation_network_replayExecuteReplay a captured network request inside an instrumentation session.
-
instrumentation_operationExecuteManage operations inside an instrumentation session.
-
instrumentation_sessionExecuteStart, stop, or query status of an instrumentation recording session. Destroying a session archives it read-only (the last 8 destroyed sessions are retained, oldest evicted) so ...
-
js_deobfuscate_pipelineExecuteThree-stage deobfuscation pipeline: preprocess → deobfuscate → humanize.
-
js_solve_constraintsExecuteSolve opaque predicates and constant expressions in obfuscated code.
-
js_symbolic_executeExecuteSymbolic execution of JavaScript: explore all feasible execution paths, collect path constraints, and solve them. Best for control-flow-flattened code with complex branching.
-
js_symbolic_execute_jsvmpExecuteSymbolic execution of JSVMP bytecode: step through instructions symbolically to infer original logic, constraints, and confidence score. Use after js_analyze_vm to get instructi...
-
manage_hooksExecuteCreate, inspect, and clear JavaScript runtime hooks.
-
memory_allocateExecuteAllocate executable memory in target process (VirtualAllocEx wrapper). Win32 only. Requires JSHOOK_INJECTION_ENABLE=1.
-
memory_auto_assembleExecuteExecute a Cheat Engine-style Auto Assembler script. Parses [ENABLE]/[DISABLE] sections and executes ENABLE commands. Supported commands: ALLOC(name,size), DEALLOC(name), LABEL(n...
-
memory_auto_assemble_disableExecuteExecute the DISABLE section of a previously-run Auto Assembler script. Pass the disableScript returned by memory_auto_assemble. Executes DISABLE commands, running DEALLOC last (...
-
memory_batch_writeExecuteWrite multiple memory patches at once. If pid is omitted, the active browser renderer PID is auto-discovered from the current browser session.
-
memory_breakpointExecuteBreakpoint via hardware debug registers (DR0-DR3) or software INT3 (0xCC). Actions: set, remove, list, trace. Hardware BPs (type=\
-
memory_call_stackExecuteWalk the call stack of a target process thread using the x64 RBP frame-pointer chain. Suspends the thread, reads the CONTEXT to get RBP/RSP/RIP, then follows the linked list of ...
-
memory_cheat_tableExecuteImport, export, sign, or verify Cheat Engine .CT files. Export: converts JSON entries to valid .CT XML. Import: parses .CT XML to JSON. Sign: HMAC-SHA256 sign the XML using a se...
-
memory_find_accessesExecuteFind what writes to or accesses a memory address (Cheat Engine MWT workflow). Sets a hardware breakpoint on the target address, auto-rearms after each hit, captures the faulting...
-
memory_first_scanExecuteStart a new memory scan session.
-
memory_freeExecuteFree remote memory in target process (VirtualFreeEx wrapper). Win32 only. Requires JSHOOK_INJECTION_ENABLE=1.
-
memory_freezeExecuteFreeze or unfreeze a memory address. Freeze continuously writes a value to prevent changes; unfreeze stops it.
-
memory_hypervisorExecuteEPT Hypervisor Phase 1: VMXON, VMCS setup, basic VM-exit handler design, CPUID spoofing. Intel VT-x only. Requires BYOVD kernel driver for MSR reads and VMXON region preparation...
-
memory_inject_dllExecuteInject a DLL into target process. Win32 only. Modes: loadlibrary (LoadLibraryW injection) or manualmap (manual mapping). Requires JSHOOK_INJECTION_ENABLE=1.
-
memory_inject_shellcodeExecuteInject shellcode into target process. Win32 only. Methods: createremote (CreateRemoteThread) or ntcreatethread (NtCreateThreadEx). Requires JSHOOK_INJECTION_ENABLE=1.
-
memory_next_scanExecuteNarrow an existing scan session. Supports delta modes: changed_by (value changed by exactly N), increased_by (value increased by at least N), decreased_by (value decreased by at...
-
memory_patch_bytesExecuteWrite bytes to target process at address. Saves original bytes for undo. Use for runtime code patching.
-
memory_patch_nopExecuteNOP out instructions at address (replace with 0x90). Useful for disabling checks or jumps.
-
memory_pointer_chainExecutePointer chain operations: scan (multi-level BFS), autoscan (auto-discover pointer chains by recursively scanning for pointers that point to or near the target address), validate...
-
memory_process_controlExecuteSuspend or resume a target process for consistent memory snapshots. Suspend freezes all threads (NtSuspendProcess on Win32, SIGSTOP on Linux, task_suspend on macOS) so memory re...
-
memory_protectExecuteChange memory page protection for a region in the target process. Wraps VirtualProtectEx (Win32) / mprotect (Linux) / mach_vm_protect (macOS). Protection: r (read-only), rw (rea...
-
memory_remoteExecuteConnect to a remote jshookmcp MCP server via WebSocket for remote debugging. Enables ceserver-style remote memory operations: connect to a remote instance, forward tool calls (m...
-
memory_scanExecuteScan process memory for a pattern or value. Requires elevated privileges. If pid is omitted, the active browser renderer PID is auto-discovered from the current browser session.
-
memory_speedhackExecuteHook time APIs (GetTickCount64/GetTickCount/QueryPerformanceCounter/QueryPerformanceFrequency/timeGetTime/GetSystemTimeAsFileTime) to scale process time via an in-process SSE2 t...
-
memory_trace_codeExecuteUltimap-style instruction-level code tracing. Sets INT3 (0xCC) software breakpoints at function entry points and logs every execution. Aggregates hit counts per address to produ...
-
memory_unknown_scanExecuteStart an unknown initial value scan.
-
memory_watchExecutePoll a memory address until its value changes (like scanmem\
-
memory_writeExecuteWrite data to process memory at a given address. If pid is omitted, the active browser renderer PID is auto-discovered from the current browser session.
-
memory_write_valueExecuteWrite a typed value to a memory address. Supports undo/redo via memory_write_history(action=undo|redo).
-
miniapp_pkg_unpackExecuteUnpack a miniapp package.
-
mojo_encode_messageExecuteEncode a structured Mojo IPC message into a hex payload.
-
mojo_monitorExecuteStart or stop Mojo IPC monitoring for the active Chromium-based target.
-
mojo_verify_liveExecuteGenerate a Frida verification script that probes a target Chromium process for known Mojo C-API exports (MojoWriteMessage, MojoWriteMessageNew) across modules. Uses a curated sy...
-
nemu_alloc_memoryExecuteAllocate raw guest memory (NOT a JNI handle — a real char* address). Optionally fill with initial data via fillBytes (base64). Returns the guest address to pass as an integer ar...
-
nemu_bind_all_importsExecuteBatch-bind host functions to ALL resolved import stubs in the GOT. Reads the GOT table (0x74000 range), finds every unique resolved address, and binds the given JS function body...
-
nemu_bind_host_fnExecuteRegister a JavaScript host function at a specific guest address, overriding any existing stub. The function receives guest registers (ctx.x(0)..x(7)), can read/write guest memor...
-
nemu_call_addressExecuteCall a function at an arbitrary guest address (e.g. a native method registered via RegisterNatives). Uses AArch64 AAPCS with args in x0..x7; returns x0. Set injectJni=true to pr...
-
nemu_call_jni_exportExecuteInvoke an exported
-
nemu_call_symbolExecuteInvoke an exported function by name following AArch64 AAPCS (integer args in x0..x7, result in x0). Auto-detects JNI signatures. Set injectJni=false to force raw arguments. Set ...
-
nemu_create_jni_handleExecuteCreate a mock JNI object handle pre-populated with controlled data. Use BEFORE calling JNI functions to seed the handle table so that GetStringUTFChars / GetObjectArrayElement /...
-
nemu_create_sessionExecuteCreate an isolated ARM64 emulator session and return its sessionId. Each session owns its own CPU registers, guest stack, and JNI object table, so concurrent analyses never inte...
-
nemu_gdbserverExecuteGDB Remote Serial Protocol (RSP) TCP server. Starts a real TCP server on host:port that GDB clients can connect to. Provides full register read/write, memory read/write, step, c...
-
nemu_load_apk_libraryExecuteExtract a specific arm64-v8a .so from an APK by name and load it into a session in one step (no temp files). Pair with nemu_extract_apk_libs to discover library names.
-
nemu_load_libraryExecuteLoad an AArch64 ELF shared object (.so) from a filesystem path into a session, mapping its segments and resolving exported symbols. Prerequisite for list_symbols / call_symbol /...
-
nemu_load_library_chainExecuteLoad a chain of dependent libraries into a session, resolving inter-library imports. Pass dependency .so paths as dependencyPaths (loaded first in order), then the primary .so p...
-
nemu_mem_mapExecuteMap a memory region in guest address space. Use to extend the mapped area for output buffers or scratch data that would otherwise cause unmapped-memory faults. Idempotent — safe...
-
nemu_new_byte_arrayExecuteWrap base64 bytes as a JNI jbyteArray handle to pass as an argument into call_jni_export (e.g. the plaintext a signing routine consumes). Returns the handle.
-
nemu_patch_applyExecuteApply multiple memory patches in a single call. Each patch is {address, dataBase64, writeProtect?}. Faster than repeated nemu_write_memory calls — essential for atomic code patc...
-
nemu_prepare_tlsExecuteMap the TPIDR_EL0 (thread-pointer) TLS block so its memory is accessible for pre-population via nemu_write_regions. Returns the TLS base address. Use this before writing data to...
-
nemu_relayExecuteConnect to a remote native-emulator session via IPC relay. Proxies nemu operations through a named pipe (Windows) or Unix domain socket (Linux/macOS) with JSON-RPC over length-p...
-
nemu_session_loadExecuteLoad a JSON-serialised array of tool calls and execute them sequentially to set up a session. Each entry is {tool, args}. Supported tools: alloc_memory, write_regions, call_addr...
-
nemu_set_registersExecuteSet arbitrary CPU registers by index. Pass an object mapping register number to value (e.g. {0: 0x60000000, 10: 0, 11: 0x55150}). Supports x0-x30 and floating-point d0-d31. Use ...
-
nemu_set_vtable_slotExecuteOverride a specific vtable slot with a custom host function. The slot at vtableAddr + slotIndex*8 is rewritten to point to a stub executing
-
nemu_traceExecuteInvoke an exported symbol while recording every instruction executed (pc, opcode, step), optionally snapshotting named registers per step. Bounded by maxSteps. Use to follow the...
-
nemu_vm_state_loadExecuteLoad VM state into guest memory. Takes ctx values and table values as hex strings and writes them at the specified base addresses. Use to bridge Python LiteVM state into native ...
-
nemu_write_memoryExecuteWrite raw bytes into guest memory at a given address via base64 data. Use to update an input buffer between call_symbol invocations without re-allocating, or to patch code/data ...
-
nemu_write_regionsExecuteWrite multiple memory regions in a single call. Accepts an array of {address, dataBase64} objects. Essential for atomic code patching: apply all patches in one call to avoid int...
-
nemu_xor_regionExecuteXOR a region of emulated memory with a single-byte key. Returns the XOR result as base64. Use for quick decryption testing — XOR a buffer with a candidate key byte and inspect t...
-
net_raw_tcp_listenExecuteListen on a local TCP port for one incoming connection.
-
net_raw_tcp_sendExecuteSend raw TCP data to a remote host; accepts hex or text input.
-
net_raw_udp_listenExecuteListen on a local UDP port for an incoming datagram.
-
net_raw_udp_sendExecuteSend a raw UDP datagram and wait for a response.
-
network_disableExecuteDisable network request monitoring
-
network_enableExecuteEnable network request monitoring.
-
network_icmp_probeExecuteRun an ICMP echo probe.
-
network_interceptExecuteManage network interception rules.
-
network_monitorExecuteManage network request monitoring.
-
network_replay_requestExecuteReplay a captured network request with optional changes.
-
network_rtt_measureExecuteMeasure round-trip time to a target URL.
-
network_tls_fingerprintExecuteCompute TLS/HTTP fingerprints for bot detection. compute_tls/compute_http build fingerprints from user-supplied lists; parse_client_hello parses a raw ClientHello record (hex) a...
-
network_tracerouteExecuteRun an ICMP traceroute.
-
page_backExecuteNavigate back in browser history.
-
page_block_scriptExecuteManage script blocking rules by URL pattern. Blocked scripts are prevented from loading/executing. Actions: add/block (add a rule), remove/unblock (remove a rule), list (show al...
-
page_clickExecuteClick a page element by CSS selector.
-
page_coverage_startExecuteStart JS+CSS code coverage collection on the active page. Coverage tracks which bytes of each loaded script/stylesheet are actually executed. Use page_coverage_stop to stop coll...
-
page_emulate_deviceExecuteEmulate a mobile device profile.
-
page_evaluateExecuteExecute JavaScript in page context.
-
page_forwardExecuteNavigate forward in browser history.
-
page_handle_dialogExecuteControl how JavaScript dialogs (alert/confirm/prompt/beforeunload) are answered. By default installs a persistent handler that auto-dismisses all dialogs. Set dismissAll=false f...
-
page_hoverExecuteHover over an element by CSS selector.
-
page_inject_scriptExecuteInject JavaScript to run on every page load.
-
page_navigateExecuteNavigate the page to a URL with wait and network options.
-
page_press_keyExecuteSimulate a key press by name.
-
page_reloadExecuteReload the current page.
-
page_script_runExecuteExecute a named script from the Script Library with optional runtime params (__params__).
-
page_scrollExecuteScroll to absolute or relative coordinates.
-
page_selectExecuteSelect option(s) in a <select> element.
-
page_set_viewportExecuteSet the browser viewport dimensions.
-
page_typeExecuteType text into an element.
-
page_wait_for_selectorExecuteWait for an element to appear.
-
payload_mutateExecuteApply deterministic byte-level mutations to a hex payload.
-
payload_template_buildExecuteBuild a deterministic payload from field definitions.
-
performance_traceExecuteStart or stop a Chrome performance trace.
-
process_detect_hollowingExecuteDetect process hollowing (malware technique that unmaps original process image and injects malicious code). Compares process memory sections (.text, .data, .rdata) with on-disk ...
-
process_launch_debugExecuteLaunch an executable with remote debugging port enabled.
-
process_resumeExecuteResume a previously suspended process. Cross-platform: NtResumeProcess (Win32), SIGCONT (Linux), task_resume (macOS).
-
process_suspendExecuteSuspend a process for forensic snapshotting. Cross-platform: NtSuspendProcess (Win32), SIGSTOP (Linux), task_suspend (macOS). Pair with process_resume to restore. Use before mem...
-
profiler_cpuExecuteStart or stop CPU profiling.
-
proxy_add_ruleExecuteAdd an interception rule: forward, mock_response, redirect, or block.
-
proxy_startExecuteStart the local HTTP/HTTPS interception proxy with optional TLS.
-
proxy_stopExecuteStop the proxy and release all active rules.
-
query_trace_sqlExecuteExecute a read-only SQL query against a trace database.
-
raw_ip_packet_buildExecuteBuild a deterministic IPv4 or IPv6 packet.
-
reload_extensionsExecuteReload plugins and workflows from configured directories, and directly register extension tools visible in the current profile.
-
reverse_sessionExecuteCreate, inspect, list, preview, or run an end-to-end reverse-engineering workflow session with artifact root, cross-domain tool calls, and evidence refs.
-
rizin_bridgeExecuteSend a command to a local Rizin/r2 analysis bridge.
-
route_toolExecuteOne-stop tool router: accepts a natural language task description, returns recommended tools and next
-
run_extension_workflowExecuteExecute an extension workflow by workflowId with optional config and timeout overrides.
-
run_macroExecuteExecute a registered macro with sequence, parallel, branch, fallback, and retry orchestration.
-
service_worker_deliver_pushExecuteDeliver a synthetic push message to a service worker via CDP ServiceWorker.deliverPushMessage. Requires an attached CDP session on a SW target.
-
service_worker_dispatch_syncExecuteDispatch a Background Sync event to a service worker via CDP ServiceWorker.dispatchSyncEvent. Requires an attached CDP session on a SW target.
-
sse_monitor_enableExecuteEnable SSE monitoring by injecting EventSource interceptor.
-
start_trace_recordingExecuteStart recording debugger traces into a SQLite database for time-travel.
-
stealth_configure_jitterExecuteConfigure CDP timing jitter.
-
stealth_injectExecuteInject anti-detection scripts to reduce bot fingerprint exposure.
-
stealth_set_user_agentExecuteSet User-Agent and fingerprint.
-
stealth_verifyExecuteRun anti-detection checks.
-
stop_trace_recordingExecuteStop trace recording and return the final session summary.
-
syscall_direct_invokeExecuteDirect NT syscall invocation guidance. Resolves SSN for a given NT function and returns a stub template with usage instructions for in-process direct syscall invocation. Bypasse...
-
syscall_ebpf_attachExecuteLive eBPF syscall attach — spawns a bpftrace process, captures syscall events as structured JSON in real time, and returns them directly. Unlike syscall_ebpf_trace (script-gener...
-
syscall_ebpf_traceExecuteTrace syscalls on Linux with eBPF. Requires root or CAP_BPF.
-
syscall_resolve_ssnExecuteResolve NT syscall service numbers (SSN) from on-disk ntdll.dll. Parses the export table to extract Zw* → SSN mappings and locates a syscall;ret gadget for direct invocation stu...
-
syscall_stack_captureExecuteCorrelate captured syscall events with real JS call stacks via debugger integration. Goes beyond static heuristics by querying live CDP call stacks for syscall→JS mapping. Falls...
-
syscall_start_monitorExecuteStart syscall monitoring.
-
syscall_stop_monitorExecuteStop syscall interception and release all captured events.
-
tab_workflowExecuteCross-tab coordination.
-
tasks_cancelExecuteRequest cancellation of a background task (MCP 2.0 Tasks protocol). Only tasks in the working state can be cancelled; the tool-defined cancel handler runs if present.
-
tcp_closeExecuteClose an open TCP session.
-
tcp_openExecuteOpen a TCP session.
-
tcp_writeExecuteWrite data to an open TCP session.
-
tls_cert_pin_bypass_fridaExecuteBypass certificate pinning via Frida injection (supports the target TLS library and HTTP client frameworks).
-
tls_closeExecuteClose an open TLS session.
-
tls_decrypt_payloadExecuteDecrypt a TLS payload using a provided key, nonce, and algorithm.
-
tls_keylog_enableExecuteEnable SSLKEYLOGFILE output for TLS library clients.
-
tls_openExecuteOpen a TLS session.
-
trace_recordingExecuteStart or stop trace recording into a SQLite database.
-
transform_workbenchExecuteRun a reproducible binary transform workbench over base64 inputs: base64, hex, XOR, RC4, AES-CBC/ECB decrypt, zlib/gzip inflate, entropy, previews, and magic hints.
-
understand_codeExecuteRun semantic code analysis for structure, behavior, and risks.
-
unidbg_callExecuteCall a JNI function in a running Unidbg emulator session.
-
unidbg_emulateExecuteEmulate a native function with Unidbg when available.
-
unidbg_launchExecuteEmulate a native shared library in Unidbg.
-
unidbg_traceExecuteGet execution trace from Unidbg session with configurable detail.
-
v8_deopt_traceExecuteTrace V8 deoptimization events during a capture window. Primary path uses CDP Tracing (v8 category, V8.DeoptimizeFrame events — no natives syntax needed, structured reason/type/...
-
v8_heap_samplingExecuteCollect a V8 allocation sampling profile via CDP HeapProfiler. Starts sampling for a capture window (default 5s), then returns the aggregated allocation call tree: per-function ...
-
v8_turbofan_graphExecuteCollect and visualize V8 TurboFan IR (sea-of-nodes / Turboshaft graph). Two modes: (1) Provide JS source code — spawns an isolated V8 child with --trace-turbo to generate IR JSO...
-
v8_turbofan_inspectExecuteInspect JIT/TurboFan compilation state for functions in a script. Reports optimization tier (interpreted/maglev/turbofan) with V8 optimization status codes. Supports actions: in...
-
v8_type_profileExecuteAtomic primitive: start or stop V8 type profiling via CDP Profiler.startTypeProfile() / takeTypeProfile() / stopTypeProfile(). Type profiles record the runtime types flowing thr...
-
wasm_instrument_binaryExecuteReal wasm-level binary instrumentation: disassembles via wasm2wat, inserts a call to an imported trace function at every function entry, and reassembles via wat2wasm. Unlike was...
-
wasm_instrument_blockExecuteReal wasm-level basic-block instrumentation: disassembles via wasm2wat, inserts a call to an imported trace function at every block/loop/if body entry (and function entry), and ...
-
wasm_instrument_traceExecuteGenerate a JS instrumentation wrapper for a .wasm module.
-
wasm_offline_runExecuteRun an exported .wasm function.
-
wasm_optimizeExecuteOptimize a .wasm binary for size or speed.
-
wasm_to_cExecuteTranspile .wasm bytecode to C source and header files.
-
watchExecuteManage watch expressions for monitoring variable values during debugging.\n\nActions:\n- add: Add a watch expression (requires expression)\n- remove: Remove by watchId\n- list: ...
-
webcrack_unpackExecuteRun webcrack bundle unpacking and return extracted module graph.
-
webgpu_frame_timingExecuteMeasure per-frame CPU and GPU cost over a rAF loop using GPU timestamp queries (device.limits.timestampPeriod conversion). Answers
-
webgpu_shader_compileExecuteCompile WGSL shader and extract metadata (entry points, bindings, attributes). Validates shader code and detects potential security issues.
-
webgpu_timing_analysisExecuteGPU timing analysis for side-channel detection. Measures GPU command execution time variance to detect cache-based side-channel attacks (Graz University 2025 research).
-
websocket_openExecuteOpen a WebSocket session.
-
websocket_send_frameExecuteSend a WebSocket frame.
-
widget_challenge_solveExecuteSolve a widget challenge with hook, manual, or configured external service.
-
workflow_conditional_stepExecuteEvaluate a condition against the stepResults argument and execute one of two tool branches. Supports built-in predicates: always_true, always_false, any_step_failed, success_rat...
-
ws_monitorExecuteEnable or disable WebSocket frame capture.
-
ws_send_frameExecuteSend a frame through a live in-page WebSocket instance retained by ws_monitor(exposeInstances=true). Enables edit-and-resend replay of WebSocket traffic. Only reaches WebSockets...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.