# Hx0 HawkEye: browser capture without touching the system proxy

> A Chrome and Firefox extension that captures, intercepts, modifies and replays HTTP and WebSocket traffic from the browser sidebar, with micro fuzzing, hidden link detection and optional AI analysis. The repository ships finished release ZIPs rather than a source tree, so installation is a download.

**asaotomo/Hx0-HawkEye** — 一个轻量级浏览器抓包与安全分析扩展，在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。（A lightweight browser extension for traffic capture and security analysis, enabling capture, interception, modification, replay, rule-based detection, and AI-assisted analysis—all from the browser sidebar.）

- Repository: https://github.com/asaotomo/Hx0-HawkEye
- Website: https://www.hx0.store/products/hawkeye
- Stars: 85 · Forks: 7
- Language: Unknown
- License: not declared
- Published: 2026-08-27 · Updated: 2026-08-27 · Language: en
- Canonical page: https://hysenlabs.com/projects/asaotomo-hx0-hawkeye

## The repository ships two release ZIPs, not a build

Start with what is actually in the tree, because it changes what installing means. The repository root holds Hx0-HawkEye-Chrome-V1.0.6-Official.Release.zip, Hx0-HawkEye-Firefox-V1.0.6-Official.Release.zip, README.md and README_EN.md. There is no source directory, no build configuration and no licence file at the root, so this is a distribution repository rather than a development one, and the English and Chinese READMEs are the documentation. Installation means taking one of those ZIPs and loading the extension into a browser, and the upgrade note in the changelog is specific about what has to be replaced: the extension and the MJS file, followed by a restart of the MCP Host. Version 1.0.6 was released on 26 August 2026, the previous two official releases are 1.0.5 and 1.0.4 from June, and the last commit on the branch is 20 September 2026. The product page lives at hx0.store/products/hawkeye.

## Capture works without Burp, a system proxy, or Java

The design premise is that engineers working on an SPA keep switching between the real browser session and a proxy tool, and the two do not agree about cookies or login state. Traditional proxies such as Burp have a high ceiling but require changing the system proxy and trusting a certificate, and a lightweight extension next to the address bar usually lacks persistent history and structured detail. Hx0 HawkEye sits between those options. Basic capture needs none of the proxy setup: no Burp, no system proxy change, no Java configuration. The optional MCP path does require Node.js installed separately. Capture records the page's fetch and XHR calls alongside browser request events, filterable by domain or IP wildcard, resource type and suffix, and WebSocket traffic shows the handshake plus OUT and IN frames. One limit is stated plainly: the request body and the raw response body depend on what the browser is willing to provide and on size limits.

## Chrome has passive listening, Firefox removed the switch

The two browsers are not treated as identical, and the differences are named rather than smoothed over. Chrome offers a full response body through passive listening, but only for requests the browser allows an extension to read. Firefox provides no corresponding switch, and the 1.0.6 notes record that its invalid version of the toggle was removed rather than left in place. The same split shows up in the sidebar, response body retrieval and intercept prompts, with the detailed limits pushed to the in-extension user manual. Elsewhere the same notes are candid about a proxy splitter behaviour change: enabling it for the first time with no upstream proxy filled in now opens the configuration and focuses the input instead of failing, a Firefox SOCKS5 username and password combination that was being wrongly rejected has been fixed and verified against a local authenticated proxy in a real browser, and Chrome SOCKS plus Firefox SOCKS4 still do not support that authentication method.

## History lives in IndexedDB and its scope has three settings

Captured traffic is persisted in IndexedDB rather than kept in memory, which is what makes a session of investigation survive closing the sidebar. The history view filters by type, Host, method, status code, sensitive hits and free text search, and its scope selector has exactly three values: traffic for the current domain, traffic for the current tab, or all capture records. Version 1.0.6 fixed the tab filter across subdomains, which was the kind of detail that made the current-tab scope quietly wrong on a site with several subdomains. The extension badge updates with the number of captures for the current site, so the count is visible without opening the panel. Interception is the other half of this pair: a queue that pauses matching HTTP requests and WebSocket frames in both directions, refreshing automatically, where each item can be edited, allowed, dropped or handled in bulk, sharing its target rules with the capture side rather than keeping a separate configuration.

## The replay workbench opens Pretty and keeps your edits

A captured request opens in the replay workbench in Pretty form, and both Pretty and Raw edits can be replayed directly, with the modifications preserved when you switch between the two views. Around that sit undo and redo, switching the target, and optional AI generated use cases. The detail audit view is where the reading happens: Pretty, Raw and Hex, response rendering in a sandbox, aggregated and highlighted sensitive information, a click on the title to copy the full URL, a download of the raw request and response as a two column text file, and a Burp style export for people who still want the traffic elsewhere. WebSocket frame replay is narrower and the notes say so: it uses a connection inside the page that is still OPEN, so it depends on the page keeping the socket alive. In-page replay is listed under the PRO tier rather than with the ordinary workbench.

## Micro fuzz marks injection points with a section sign

The micro fuzzer marks its injection points inline with the §...§ notation, which means you choose the injection points inside the actual value rather than maintaining a dictionary of whole payloads. Two entry points exist, Start Fuzz and in-page Fuzz, the latter working against HTTP or the DOM. WebSocket micro fuzzing is serial: it sends one message at a time and treats the next inbound frame as the result, so it depends on an active connection in the page. Baseline comparison lets you diff a run against the unmodified behaviour, and the AI payload option has the model generate candidate payloads from the injection context rather than you writing them by hand. Alongside it sits a codec and hashing panel covering MD5, SM3, SHA, ROT13, Base64, URL and Hex, where the scope is chosen per action: the selected text, only parameter values, or the whole URL line. That scope choice is the detail that decides whether a decode is useful.

## AI reads captured evidence and admits a missing body

The AI features are optional and bring your own key. Single packet analysis works on the request and response evidence that was actually captured, and when the raw response body is unavailable it explains why rather than presenting a replay result as if it were the original response. Batch analysis runs in its own workbench where you select several packets and the model extracts patterns across interface families and third party calls, which is aimed at supply chain and dependency surface screening rather than at a single request. Hidden link detection combines rule scanning over static HTML with optional AI interpretation, and the results are explicitly left for a human to verify. Providers named are OpenAI, DeepSeek, Grok, MiniMax, Gemini, Ollama and LM Studio as local options, plus custom endpoints, and the 1.0.6 notes record that model candidates and provider key isolation were updated. Requests go to the service you configure.

## Tiers, agent hosts, and Skills you have to enable twice

The product is layered as a community edition, a PRO edition and a first trial of 30 minutes of PRO after install. The community line covers the daily path: capture with basic WebSocket observation, detail view, ordinary replay including WebSocket frame replay, basic codec work, and intercept plus modify for HTTP and for WebSocket frames that match a rule. PRO adds in-page replay and fuzz, HTTP and WebSocket micro fuzzing, userscripts, AI, the AI task desk, the Skills knowledge base, hidden link detection, the batch workbenches and the advanced codecs. 1.0.6 moved the smart agent splitter, full depth search, and the built-in and custom sensitive matching with keyword libraries into the community edition. The PRO MCP exposes browser navigation and the HawkEye tools to an agent host such as Codex, Cursor or LM Studio over stdio, Streamable HTTP or legacy SSE, with the local server at 1.0.13. Skills take two deliberate steps: new agent sessions start with them off, and you must enable the allowed skills in advanced settings before clicking Skills for that session.

## Conclusion

Hx0 HawkEye fits someone who already works inside a logged-in browser tab and wants to see, pause, edit and replay that traffic without setting up a proxy and a certificate, and it fits a security reviewer working inside an authorised scope who wants the evidence and the AI notes in one place. Three things to know before you rely on it. Response bodies are bounded by what the browser will hand an extension, so Chrome's passive listening covers only permitted requests and Firefox has no equivalent switch at all. The AI analysis is BYOK and reads captured evidence, and the notes say so when a raw body is missing rather than passing a replay result off as one. And a good part of the depth, including in-page replay, micro fuzz, the AI task desk and the Skills knowledge base, sits behind the PRO tier, with 30 minutes of it offered on first install. Version 1.0.6 shipped on 26 August 2026 and the last push is 20 September 2026.

## FAQ

### What is Hx0 HawkEye?

It is a lightweight security workbench extension for Chrome, Firefox and mainstream Chromium browsers. It works inside your real tab and login state and unifies capture and interception with modification including WebSocket, traffic replay, micro fuzzing, sensitive information and hidden link detection, AI security audit, MCP and a browser level agent.

### Does Hx0 HawkEye need Burp or a system proxy for basic capture?

No. Basic capture works without opening Burp, without changing the system proxy and without configuring Java. Optional MCP access is the part that needs Node.js installed separately.

### What can the community edition of Hx0 HawkEye do?

It covers the everyday chain: capture with basic WebSocket observation, detail view, ordinary replay including WebSocket frame replay, and basic codec work, plus intercept and modify for HTTP and for WebSocket frames that match a rule. PRO adds in-page replay and fuzz, micro fuzzing, userscripts, AI, the AI task desk, Skills, hidden links and the batch workbenches.

### How do I install Hx0 HawkEye?

The repository root carries the official Chrome and Firefox 1.0.6 release ZIP files alongside the Chinese and English READMEs. Upgrading means replacing the extension and the MJS file and restarting the MCP Host. The product page is at hx0.store/products/hawkeye.

### How does Hx0 HawkEye connect an AI agent host?

Through its PRO MCP: once a host such as Codex, Cursor or LM Studio connects hx0-hawkeye, the model can call browser and HawkEye tools to control real tabs, over stdio, Streamable HTTP or legacy SSE. The local MCP server is at 1.0.13, and the standalone hawkeye-mcp-server.mjs stays directly runnable for troubleshooting while the extension scripts inside the ZIP are obfuscated.

## Sources

- [Official documentation](https://www.hx0.store/products/hawkeye)
- [Official README](https://github.com/asaotomo/Hx0-HawkEye#readme)
- [Project repository](https://github.com/asaotomo/Hx0-HawkEye)
- [Release notes](https://github.com/asaotomo/Hx0-HawkEye/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/asaotomo-hx0-hawkeye
