Anything Analyzer: Browser Capture, an MITM Proxy and MCP in One Electron App
全能协议分析工具:浏览器抓包 + MITM 代理 + 指纹伪装 + AI 分析 + MCP Server 无缝对接 AI Agent/IDE | All-in-one protocol analysis toolkit — built-in browser capture, MITM proxy, JS hooks, fingerprint spoofing, AI analysis & MCP server for agent integration
At a glance
- What is it?
- Anything Analyzer is a TypeScript and Electron desktop tool that merges an embedded CDP browser, an HTTPS man-in-the-middle proxy on port 8888 and an AI analysis pipeline. It suits engineers reverse-engineering APIs, but its MITM design has real blind spots.
- Who is it for?
- Adopt Anything Analyzer if you reverse-engineer HTTP and HTTPS APIs across browsers, CLI tools and mobile apps and want the captured traffic summarised by an LLM rather than read by hand. Do not adopt it for WebSocket payload inspection, for binary or large-body protocols, or for anything where you cannot install a root CA on the target device.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 13 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 17, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Anything Analyzer Actually Solves
The project's own framing is that the existing tools each cover one slice. DevTools sees only the browser. Fiddler and Charles are proxies but not analysis environments. Wireshark cannot read HTTPS without keys. After capturing, you still scroll through hundreds of requests by hand.
Anything Analyzer's answer is to funnel every source into one session object and then hand that session to an LLM. The README lists six capture targets: web pages through an embedded browser, desktop apps through system proxy settings, terminal commands such as curl and wget, scripts using Python requests or Node.js fetch, phones and tablets over Wi-Fi proxy settings, and IoT devices through a gateway proxy. All of them land in the same Session, and the AI analysis step processes them together.
The intended user is someone doing black-box protocol work: reverse-engineering a site's API, recovering a mobile app's request signing logic, or auditing a service for leaked tokens and CSRF issues. It is a desktop application, not a library, so the audience is the engineer at a keyboard, not a CI pipeline.
How the Capture Pipeline Is Wired
The repository layout in the README shows the architecture plainly. Under src/main, capture holds the CDP Fetch interception and JS hook injection, cdp manages the Chrome DevTools Protocol connection, proxy holds the MITM proxy with CA management and certificate issuance, ai holds a two-stage analysis pipeline with prompt templates and LLM routing, mcp holds both an MCP client and a built-in MCP server, db is a better-sqlite3 layer, and session manages session lifecycle.
Two capture channels feed one session. The embedded browser uses CDP Fetch interception to record every HTTP request and response including headers and body. The MITM proxy handles everything outside the browser. Requests are tagged with their origin so you can tell CDP traffic from proxy traffic.
The AI side is explicitly two-phase: Phase 1 filters noise, Phase 2 does the deep analysis, and the model can pull individual request details on demand rather than being handed the whole capture at once. That matters because a session can be large. There are five analysis modes (auto, API reverse engineering, security audit, performance, and JS crypto reverse engineering), streaming output, and follow-up questions after a report is generated.
The JS hook layer is the part worth calling out. It intercepts fetch, XHR, crypto.subtle, CryptoJS and SM2/3/4 calls, and the app can extract crypto-related code fragments out of JavaScript files. That is the mechanism behind the crypto reverse-engineering mode: instead of inferring the algorithm from ciphertext, the hook sees the call site.
Installing Anything Analyzer and Capturing Your First Request
The README points to GitHub Releases rather than a package registry. Installers are named per platform: Anything-Analyzer-Setup-x.x.x.exe for Windows, Anything-Analyzer-x.x.x-arm64.dmg and Anything-Analyzer-x.x.x-x64.dmg for macOS, and Anything-Analyzer-x.x.x.AppImage for Linux.
If you would rather build from source, the README gives these commands. Note the capitalised WW in the clone URL, which differs from the owner casing used elsewhere in the repository.
git clone https://github.com/MouseWW/anything-analyzer.git
cd anything-analyzer
pnpm install
pnpm dev # development mode
pnpm test # run testspnpm dev starts the Electron app in development mode. Building a distributable is a separate step, and the README shows the Windows form of it:
pnpm build && npx electron-builder --winOnce the app is open, the README's first-run sequence for a web target is four steps: configure an LLM under Settings then LLM with an API key (OpenAI, Anthropic or any compatible endpoint), create a new Session with a name and target URL, operate the site inside the embedded browser and click Start Capture, then stop capture and click Analyze to pick an analysis mode. The README does not document a rollback for a session once analysis has run.
Pointing External Traffic at the Proxy
The proxy listens on port 8888 by default. Enabling it is a Settings step, and the README requires installing the CA certificate first. The certificate lives under %APPDATA%/anything-analyzer/certs/ on Windows and ~/Library/Application Support/anything-analyzer/certs/ on macOS, and first-time installation needs administrator rights. The root CA is valid for 10 years and leaf certificates for 825 days, which the README says is to satisfy Apple's requirements.
For a terminal command, the documented form is:
curl -x http://127.0.0.1:8888 https://api.example.com/dataThe request should appear in the active session tagged as proxy traffic. The README gives the equivalent configuration for a Python script and for Node.js:
proxies = {"http": "http://127.0.0.1:8888", "https": "http://127.0.0.1:8888"}
requests.get("https://api.example.com/data", proxies=proxies)HTTP_PROXY=http://127.0.0.1:8888 HTTPS_PROXY=http://127.0.0.1:8888 node app.jsFor desktop applications, Settings has a one-click option to set the system proxy. For a phone or tablet, the README says to set Wi-Fi HTTP proxy to manual with the computer's IP and port 8888, then open the proxy address in the phone browser to download and install the CA certificate. A session created with an empty URL still receives that external traffic.
Where the MITM Design Stops
The README is unusually candid in its CA certificate section, and the limits it names are the ones to take seriously. The MITM proxy is read-only capture: it does not modify request or response content. WebSocket traffic is tunnelled, not decrypted. Individual bodies are capped at 1MB, and binary content is skipped automatically.
That combination rules out a set of jobs. If your target protocol runs over WebSocket, the app will show you the upgrade request and then nothing useful about the frames. If you are analysing a binary protocol, a protobuf-heavy service, or anything transferring files larger than 1MB, the body will not be there. And because modification is off the table, you cannot use it to replay a tampered request or test how a server reacts to an altered signature.
The certificate handling is the other boundary. Installing a root CA on a device is a real change to that device's trust store, and on iOS and recent Android versions it can require more than a settings toggle. Anything Analyzer gives you install, uninstall, regenerate and export actions, but the README notes the first install needs admin rights (Windows UAC or macOS password). On a machine you do not control, that alone can be a blocker.
There is also a packaging caveat that has nothing to do with capture: the README warns that macOS auto-update depends on signed and notarised builds, and that GitHub Actions needs CSC_LINK, CSC_KEY_PASSWORD, APPLE_ID, APPLE_APP_SPECIFIC_PASSWORD and APPLE_TEAM_ID configured in repository Secrets or ShipIt cannot install updates. That is a maintainer concern, but it tells you the macOS update path is more fragile than the Windows one.
Anything Analyzer vs Charles and mitmproxy
The honest comparison is with mitmproxy, because that is the tool most people reach for when they need a scriptable HTTPS proxy.
mitmproxy is a Python program with a console UI, a web UI and a scripting API. You write addons in Python, run them headless, and put the whole thing in CI. Its strength is that interception logic is code you own and version. Its weakness for this use case is that it does not analyse anything for you: you still read the flows.
Anything Analyzer inverts both properties. The proxy is a component inside a GUI, not a standalone process you script, and the value comes from the AI layer summarising what was captured. You get a two-phase pipeline, five analysis modes and follow-up questions out of the box, plus MCP so Claude Desktop or Cursor can call the capture tools directly. You give up headless operation and the ability to write your own interception logic.
Charles sits between the two: a mature commercial GUI proxy with strong mapping and rewriting features. Anything Analyzer's proxy is explicitly read-only, so if rewriting responses is part of your workflow, Charles or mitmproxy is the right tool and Anything Analyzer is not.
The MCP angle is the genuinely different piece. The README describes both directions: an MCP client that connects to external MCP servers over stdio and StreamableHTTP to extend analysis, and a built-in MCP server that exposes capture and analysis as tools for other agents. If your workflow already lives in an agent IDE, that is the reason to pick this over a plain proxy.
Licence, Maintenance and Upgrade Cost
The README carries an MIT badge linking to a LICENSE file, but the top-level repository listing does not include a LICENSE file. Treat the licence as unverified until that file exists, and read it before you ship anything derived from the source. Nothing here is legal advice; if the distinction matters to your organisation, ask someone qualified.
The last push was on 2026-09-09, and the most recent release listed is v3.6.61 from 2026-08-26. The version in package.json is 3.6.62. Releases have been frequent, with three listed between early August and late August 2026, and the version numbering suggests small increments rather than long cycles.
Upgrade cost is mostly operational rather than code-level, since this is an installed desktop app. Auto-update is built in via electron-updater. The friction is on macOS, where the README ties updates to signed and notarised packages. Building from source needs Node.js 18 or newer, pnpm (package.json pins [email protected]), and Visual Studio Build Tools on Windows, which better-sqlite3 makes necessary. The stack is Electron 35, React 19, Ant Design 5, TypeScript 5 and better-sqlite3, so anyone forking it inherits a full Electron toolchain rather than a small script.
Editorial conclusion
Adopt Anything Analyzer if you reverse-engineer HTTP and HTTPS APIs across browsers, CLI tools and mobile apps and want the captured traffic summarised by an LLM rather than read by hand. Do not adopt it for WebSocket payload inspection, for binary or large-body protocols, or for anything where you cannot install a root CA on the target device. Before committing, verify three things: that the repository has no LICENSE file even though the README badge says MIT, that your chosen LLM endpoint works with the Chat Completions or Responses API the app routes to, and that the MITM proxy's read-only, non-decrypting WebSocket behaviour matches what you actually need to inspect.
Frequently asked questions
How do I install Anything Analyzer?
Download the installer for your platform from the GitHub Releases page: Anything-Analyzer-Setup-x.x.x.exe for Windows, the arm64 or x64 .dmg for macOS, or the .AppImage for Linux. Building from source instead requires Node.js 18 or newer and pnpm, then pnpm install followed by pnpm dev.
Does Anything Analyzer decrypt WebSocket traffic?
No. The README states that WebSocket traffic is tunnelled and not decrypted, so the app detects the upgrade request but does not expose the frames. The MITM proxy is also read-only and does not modify requests or responses.
What are the limits on captured request bodies in Anything Analyzer?
The README documents a 1MB cap on a single body, and binary content is skipped automatically. Larger payloads and binary protocols therefore will not appear in the captured data.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/mouseww-anything-analyzer)