crissyfield/super-trouper

MCP server for Frida.

Go

39

49 commits

updated Sep 27, 2026

See the code

See what people are saying

SourceMessageScoreDate

Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering (r/mcp)

I’m the author of **Super Trouper**, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup. We…

1

Oct 2, 2026

README

super-trouper logo

Super Trouper

An MCP server for the Frida reverse engineering toolkit.

Super Trouper runs an MCP server over STDIO that exposes Frida capabilities as tools for coding agents. It can connect to local, USB, and remote devices; inspect applications and processes; manage process sessions; and load, evaluate, and exchange messages with JavaScript instrumentation scripts. It can also search Frida CodeShare to discover community scripts and fetch them for use with the scripting tools. Device connections, sessions, and scripts are managed through the tools themselves and referenced by opaque handles.

super-trouper

Features

  • Single Go binary — no Python, Node, or Frida CLI tooling required on your host
  • Powered by Frida 17.x — statically linked against Frida Core DevKit v17.19.0
  • Full device support — list and connect to local, USB, and remote devices, attach to apps and processes
  • TypeScript and JavaScript instrumentation — create and load Frida scripts, evaluate directly in a target
  • Frida CodeShare integration — search, browse, and fetch the CodeShare catalog of community scripts
  • Runs anywhere — prebuilt binaries for macOS and Linux, install via Docker, Homebrew, or npm

Install

Homebrew

Install the macOS release through the project’s Homebrew tap:

brew install --cask crissyfield/tap/super-trouper

npm

Install the launcher package through npm. It pulls in the platform-specific binary via optional dependencies:

npm install -g @crissyfield/super-trouper

Release Binary

Download a binary for your platform from the Releases page.

From Source

Install a Frida Core DevKit matching your build host first. Then build and install Super Trouper with the following commands:

# Set flags if the Frida devkit is not in a standard location
export CGO_CFLAGS="-I/path/to/frida-core-devkit/include"
export CGO_LDFLAGS="-L/path/to/frida-core-devkit/lib"

# Build and install
export CGO_ENABLED=1
go install github.com/crissyfield/super-trouper@latest

Usage

Use the MCP server in your coding agent. Claude Code is the example below, but configuration is similar in Codex, OpenCode, Pi, Crush, and others.

Using the Binary

If the Super Trouper binary is not in your PATH, specify the full path in your MCP server configuration.

{
  "mcpServers": {
    "super-trouper": {
      "command": "super-trouper"
    }
  }
}

Using npx

npm users can run Super Trouper directly through npx without a global installation:

{
  "mcpServers": {
    "super-trouper": {
      "command": "npx",
      "args": ["-y", "@crissyfield/super-trouper"]
    }
  }
}

Using Docker

Docker is a convenient way to run Super Trouper without installing it on your host.

{
  "mcpServers": {
    "super-trouper": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "ghcr.io/crissyfield/super-trouper"]
    }
  }
}

MCP Tools

Super Trouper exposes the following MCP tools:

ToolDescription
app_listLists the applications installed on a Frida device.
app_findFinds an application on a Frida device by identifier or name.
app_frontmostReturns the frontmost application on a Frida device.
codeshare_searchSearches Frida CodeShare for projects matching the given query.
codeshare_popularLists the most popular projects on Frida CodeShare.
codeshare_projectReturns a project from Frida CodeShare, including its JavaScript source, which can be run with the other scripting tools.
device_listLists the Frida devices detected by the host.
device_connectConnects to a Frida device by ID reported by device_list, by a remote Frida server address, or by type. Returns a device handle used by the other device tools; reconnecting to the same device returns the existing handle.
device_disconnectDisconnects from a Frida device. Fails while the device still has attached sessions.
device_paramsReturns the parameters of a Frida device.
device_spawnSpawns a process on a Frida device in a suspended state. Use device_resume to start it.
device_resumeResumes a suspended process on a Frida device.
device_killKills a process on a Frida device.
memory_readReads up to 4096 bytes of memory in an attached process and returns it as hex, base64, UTF-8, or a NUL-terminated C string. Fails if any byte of the range cannot be read.
memory_writeWrites up to 4096 bytes of memory in an attached process as hex (default) or base64, selected with the encoding parameter. Fails if memory cannot be written; patching code is out of scope.
module_listLists the modules loaded in an attached process. Results can be matched by name or path and paginated.
process_listLists the processes running on a Frida device.
script_createCreates a Frida script with TypeScript source in an attached session. The script is created unloaded; use script_load to load it.
script_loadLoads a Frida script into its target process.
script_unloadUnloads a Frida script from its target process.
script_closeUnloads a Frida script if loaded and releases its resources.
script_postPosts a JSON message to a Frida script.
script_messagesReturns messages sent by a Frida script. Messages are buffered (up to 256) and should be drained regularly.
script_bridge_listReturns the language bridges that can be exposed as globals in scripts created with script_create.
session_attachAttaches to a process on a Frida device by PID or name. Returns a session handle used by the session tools.
session_detachDetaches from a process, closing all of its scripts and its session.
session_evalEvaluates a JavaScript statement in an attached process and returns its JSON result. The first call sets up a persistent evaluator in the session.
frida_versionReturns the version of the linked Frida Core library.
frida_documentationReturns documentation links for the Frida JavaScript API.
thread_listLists the threads running in an attached process with their ID, state, and program counter.
application-security
frida
ios-security
mcp
mobile-security
model-context-protocol
pentesting
reverse-engineering

crissyfield/super-trouper

MCP server for Frida.

Go

39

49 commits

updated Sep 27, 2026

See the code

See what people are saying

SourceMessageScoreDate

Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering (r/mcp)

I’m the author of **Super Trouper**, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup. We…

1

Oct 2, 2026

README

super-trouper logo

Super Trouper

An MCP server for the Frida reverse engineering toolkit.

Super Trouper runs an MCP server over STDIO that exposes Frida capabilities as tools for coding agents. It can connect to local, USB, and remote devices; inspect applications and processes; manage process sessions; and load, evaluate, and exchange messages with JavaScript instrumentation scripts. It can also search Frida CodeShare to discover community scripts and fetch them for use with the scripting tools. Device connections, sessions, and scripts are managed through the tools themselves and referenced by opaque handles.

super-trouper

Features

  • Single Go binary — no Python, Node, or Frida CLI tooling required on your host
  • Powered by Frida 17.x — statically linked against Frida Core DevKit v17.19.0
  • Full device support — list and connect to local, USB, and remote devices, attach to apps and processes
  • TypeScript and JavaScript instrumentation — create and load Frida scripts, evaluate directly in a target
  • Frida CodeShare integration — search, browse, and fetch the CodeShare catalog of community scripts
  • Runs anywhere — prebuilt binaries for macOS and Linux, install via Docker, Homebrew, or npm

Install

Homebrew

Install the macOS release through the project’s Homebrew tap:

brew install --cask crissyfield/tap/super-trouper

npm

Install the launcher package through npm. It pulls in the platform-specific binary via optional dependencies:

npm install -g @crissyfield/super-trouper

Release Binary

Download a binary for your platform from the Releases page.

From Source

Install a Frida Core DevKit matching your build host first. Then build and install Super Trouper with the following commands:

# Set flags if the Frida devkit is not in a standard location
export CGO_CFLAGS="-I/path/to/frida-core-devkit/include"
export CGO_LDFLAGS="-L/path/to/frida-core-devkit/lib"

# Build and install
export CGO_ENABLED=1
go install github.com/crissyfield/super-trouper@latest

Usage

Use the MCP server in your coding agent. Claude Code is the example below, but configuration is similar in Codex, OpenCode, Pi, Crush, and others.

Using the Binary

If the Super Trouper binary is not in your PATH, specify the full path in your MCP server configuration.

{
  "mcpServers": {
    "super-trouper": {
      "command": "super-trouper"
    }
  }
}

Using npx

npm users can run Super Trouper directly through npx without a global installation:

{
  "mcpServers": {
    "super-trouper": {
      "command": "npx",
      "args": ["-y", "@crissyfield/super-trouper"]
    }
  }
}

Using Docker

Docker is a convenient way to run Super Trouper without installing it on your host.

{
  "mcpServers": {
    "super-trouper": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "ghcr.io/crissyfield/super-trouper"]
    }
  }
}

MCP Tools

Super Trouper exposes the following MCP tools:

ToolDescription
app_listLists the applications installed on a Frida device.
app_findFinds an application on a Frida device by identifier or name.
app_frontmostReturns the frontmost application on a Frida device.
codeshare_searchSearches Frida CodeShare for projects matching the given query.
codeshare_popularLists the most popular projects on Frida CodeShare.
codeshare_projectReturns a project from Frida CodeShare, including its JavaScript source, which can be run with the other scripting tools.
device_listLists the Frida devices detected by the host.
device_connectConnects to a Frida device by ID reported by device_list, by a remote Frida server address, or by type. Returns a device handle used by the other device tools; reconnecting to the same device returns the existing handle.
device_disconnectDisconnects from a Frida device. Fails while the device still has attached sessions.
device_paramsReturns the parameters of a Frida device.
device_spawnSpawns a process on a Frida device in a suspended state. Use device_resume to start it.
device_resumeResumes a suspended process on a Frida device.
device_killKills a process on a Frida device.
memory_readReads up to 4096 bytes of memory in an attached process and returns it as hex, base64, UTF-8, or a NUL-terminated C string. Fails if any byte of the range cannot be read.
memory_writeWrites up to 4096 bytes of memory in an attached process as hex (default) or base64, selected with the encoding parameter. Fails if memory cannot be written; patching code is out of scope.
module_listLists the modules loaded in an attached process. Results can be matched by name or path and paginated.
process_listLists the processes running on a Frida device.
script_createCreates a Frida script with TypeScript source in an attached session. The script is created unloaded; use script_load to load it.
script_loadLoads a Frida script into its target process.
script_unloadUnloads a Frida script from its target process.
script_closeUnloads a Frida script if loaded and releases its resources.
script_postPosts a JSON message to a Frida script.
script_messagesReturns messages sent by a Frida script. Messages are buffered (up to 256) and should be drained regularly.
script_bridge_listReturns the language bridges that can be exposed as globals in scripts created with script_create.
session_attachAttaches to a process on a Frida device by PID or name. Returns a session handle used by the session tools.
session_detachDetaches from a process, closing all of its scripts and its session.
session_evalEvaluates a JavaScript statement in an attached process and returns its JSON result. The first call sets up a persistent evaluator in the session.
frida_versionReturns the version of the linked Frida Core library.
frida_documentationReturns documentation links for the Frida JavaScript API.
thread_listLists the threads running in an attached process with their ID, state, and program counter.
application-security
frida
ios-security
mcp
mobile-security
model-context-protocol
pentesting
reverse-engineering

Languages

Go

92.4%

Shell

4.6%

JavaScript

1.6%

TypeScript

1.2%