// the find
zhizhuodemao/js-reverse-mcp
AI Agent-first JS 逆向 MCP Server:有头 Chrome 调试、断点、网络/WebSocket 分析、Patchright 反检测,可选 CloakBrowser。
An MCP server that gives an AI coding assistant a headed Chrome for debugging JavaScript on live pages: it lists and fetches scripts, sets breakpoints, evaluates code in paused call frames, inspects network and WebSocket traffic, and exports raw material to local files. It is aimed at people doing JS reverse engineering or browser-side debugging who already work through Claude Code, Cursor, or Codex.
The tool outputs are shaped for the agent's next step. List views stay short, detail views are bounded, long results point to outputFile exports instead of flooding the context, and pending requests tell the agent to resume execution rather than wait on a response that will never arrive. The local file round trip is the most useful part: save_script_source, outputFile on network exports, and localFilePath on evaluate_script let the model work on a multi-megabyte minified bundle or a binary response without pasting it into chat. Breakpoint evaluation runs in the paused call frame, so scoped variables and single-stepping with source context stay in the same loop, and set_breakpoint_on_text is a practical shortcut for minified code where line numbers mean nothing. The repo also keeps a 30-case tool-routing contract in evals/tool-routing.json that is validated offline in presubmit, which checks whether the model picks the right tool rather than only whether the tool works.
The default mode depends on a forked Patchright package published under the maintainer's own npm scope, and the anti-detection claims are deliberately hedged, since the README says it does not promise undetectability. Anyone using this against a serious target is trusting one maintainer's fork to keep pace with Chrome releases. The --cloak path downloads a roughly 200MB binary on first launch, and the default behavior is to fetch it silently during MCP startup, which the README itself admits looks like a hang; pre-installing it is documented but not enforced. File access is unrestricted unless --allowedRoots is set, so evaluate_script.localFilePath and the outputFile options can read or write any path the process can reach, and the safer setting is opt-in and also disables file: pages when enabled. Two sponsor blocks sit above the feature list. They are disclosed, but they push the technical content down and blur which product claims come from the project and which come from the sponsors.