JavaScript Frontend Encryption Reversal: Tools and Techniques in reverse-skill
The zhaoxuya520/reverse-skill repository provides a dedicated js-reverse skill that bundles MCP-based network capture, source analysis, and browser debugging tools to systematically reverse engineer client-side encryption schemes.
The js-reverse skill within the reverse-skill repository offers a comprehensive toolkit for JavaScript frontend encryption reversal, enabling security researchers to intercept, analyze, and reconstruct cryptographic workflows executed in browser environments. Located in skills/js-reverse/SKILL.md, this skill integrates directly with Chrome DevTools Protocol (CDP) and Node.js to automate the extraction of obfuscated algorithms and encryption keys from minified production code.
Core Tools for Network and Source Analysis
Effective reversal begins with observing encrypted traffic and locating the responsible scripts. The repository provides several specialized commands for this discovery phase.
Network Traffic Capture and Request Locating
The js-reverse_list_network_requests command fetches network logs from the browser, automatically handling pagination when dealing with high-volume traffic. To trace which specific script initiated an encrypted request, use js-reverse_get_request_initiator followed by the request ID. These behaviors are defined in skills/js-reverse/references/tool-defaults.md.
Source Code Discovery and Retrieval
Once a suspicious request is identified, locate the encryption logic using js-reverse_search_in_sources, which searches script sources while excluding minified files by default to reduce noise. For extracting the actual code:
js-reverse_get_script_source– retrieves small script fragments for quick inspectionjs-reverse_save_script_source– downloads complete script files for local analysis
Runtime Debugging and Browser Control
After locating the target scripts, the toolkit provides commands to pause execution and inspect the runtime state.
Breakpoint Management and State Inspection
Set precise interception points using:
js-reverse_break_on_xhr– sets breakpoints on stable URL fragments to catch XHR/fetch requests at the moment encryption occursjs-reverse_set_breakpoint_on_text– sets breakpoints when specific code patterns are executedjs-reverse_get_paused_info– inspects the first frame (frameIndex=0) when execution pauses, revealing variable states and call stacks
Page and Frame Navigation
Control the browser context using js-reverse_new_page, js-reverse_navigate_page, js-reverse_select_page, and js-reverse_select_frame to open targets and isolate specific execution contexts where encryption routines run.
Deep Instrumentation with jshookmcp
For complex scenarios involving WebAssembly, dynamic script injection, or heavily obfuscated code, the repository integrates jshookmcp. This MCP-based hook enables deep CDP interactions, network interception, AST analysis, and source-map resolution. According to skills/routing.md, jshookmcp activates enhanced instrumentation beyond the standard js-reverse command set, exposing hidden variables and runtime memory that standard breakpoints might miss.
The Five-Stage Reversal Workflow
As documented in skills/js-reverse/SKILL.md, the tools operate within a structured Observe → Capture → Rebuild → Verify → Evidence pipeline:
- Observe – Use network capture and source search to identify the encryption entry point
- Capture – Set breakpoints and extract the cryptographic functions
- Rebuild – Evaluate scripts locally to isolate the encryption logic
- Verify – Test reconstructed algorithms against captured payloads
- Evidence – Document findings with screenshots and exported scripts
Practical Implementation: Capture and Rebuild Sequence
Below is a complete workflow for extracting a frontend encryption routine:
# 1️⃣ Open the target page
js-reverse_new_page https://example.com/login
# 2️⃣ Locate the request carrying the encrypted payload
js-reverse_list_network_requests
# → Note the request ID for /api/auth
# 3️⃣ Trace the JavaScript function that builds the payload
js-reverse_get_request_initiator <request-id>
# → Returns calling script and function name
# 4️⃣ Search source code for encryption routines
js-reverse_search_in_sources "encrypt|obfuscate|crypto"
# 5️⃣ Retrieve the full script for local analysis
js-reverse_get_script_source <script-id> > auth.js
# 6️⃣ Evaluate the routine in Node.js to extract the key
js-reverse_evaluate_script "extractKey(auth.js)" > key.txt
# 7️⃣ Reconstruct the request locally with recovered parameters
node reconstruct.js --key key.txt --payload <captured-payload>
For cases requiring deeper inspection, enable the advanced hook:
# Activate enhanced CDP instrumentation
jshookmcp enable
# Re-run steps 1-7 with memory inspection and hidden variable exposure
Infrastructure and Dependencies
The underlying execution environment relies on Node.js tooling registered in skills/scripts/refresh-tool-index.sh, which configures node and npx as executables for the js-reverse skill. System compatibility is verified through skills/scripts/lib/ToolDiscovery.ps1, which detects the presence of both js-reverse and jshookmcp binaries on the host system. Command defaults and pagination behaviors are further specified in skills/js-reverse/references/tool-defaults.md.
Summary
- The
js-reverseskill inzhaoxuya520/reverse-skillprovides specialized commands for JavaScript frontend encryption reversal via MCP integration js-reverse_list_network_requestsandjs-reverse_search_in_sourceshandle initial traffic and code discoveryjs-reverse_break_on_xhrandjs-reverse_get_paused_infoenable runtime inspection of encryption routinesjshookmcpoffers advanced instrumentation for WebAssembly and dynamically injected scripts- The toolkit follows a five-stage workflow defined in
skills/js-reverse/SKILL.md: Observe, Capture, Rebuild, Verify, and Evidence - Execution depends on Node.js (
node/npx) registered inskills/scripts/refresh-tool-index.sh
Frequently Asked Questions
What is the primary purpose of the js-reverse skill?
The js-reverse skill provides a structured toolchain for intercepting and analyzing encrypted network traffic generated by browser-based JavaScript. It combines CDP-based debugging with Node.js execution to extract and reconstruct client-side encryption algorithms that would otherwise remain obfuscated in production builds.
How does jshookmcp differ from standard js-reverse commands?
While standard js-reverse_* commands handle network capture and breakpoint management, jshookmcp provides deeper browser instrumentation by exposing CDP internals, AST structures, and source-map resolutions. Use jshookmcp when reversing WebAssembly modules or scripts that employ dynamic code generation techniques that evade conventional breakpoints.
Where are the default behaviors for these tools documented?
Tool behaviors, including auto-pagination settings for network requests and minified-file exclusions for source searches, are documented in skills/js-reverse/references/tool-defaults.md. The routing logic that selects js-reverse for JavaScript encryption tasks is defined in skills/routing.md.
What system dependencies are required to run these reversal tools?
The toolchain requires Node.js and npm/npx, registered as executables in skills/scripts/refresh-tool-index.sh. The PowerShell script at skills/scripts/lib/ToolDiscovery.ps1 verifies that both the standard js-reverse utilities and the optional jshookmcp hook are available in the system path before execution.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →