# Anything Analyzer: Browser Capture, an MITM Proxy and MCP in One Electron App

> Anything Analyzer is a TypeScript and Electron desktop tool that merges an embedded CDP browser, an HTTPS man-in-the-middle proxy on port 8888 and an AI analysis pipeline. It suits engineers reverse-engineering APIs, but its MITM design has real blind spots.

**Mouseww/anything-analyzer** — 全能协议分析工具：浏览器抓包 + MITM 代理 + 指纹伪装 + AI 分析 + MCP Server 无缝对接 AI Agent/IDE   |  All-in-one protocol analysis toolkit — built-in browser capture, MITM proxy, JS hooks, fingerprint spoofing, AI analysis & MCP server for agent integration

- Repository: https://github.com/Mouseww/anything-analyzer
- Stars: 3,666 · Forks: 645
- Language: TypeScript
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/mouseww-anything-analyzer

## What Anything Analyzer Actually Solves

The project's own framing is that the existing tools each cover one slice. DevTools sees only the browser. Fiddler and Charles are proxies but not analysis environments. Wireshark cannot read HTTPS without keys. After capturing, you still scroll through hundreds of requests by hand.

Anything Analyzer's answer is to funnel every source into one session object and then hand that session to an LLM. The README lists six capture targets: web pages through an embedded browser, desktop apps through system proxy settings, terminal commands such as curl and wget, scripts using Python requests or Node.js fetch, phones and tablets over Wi-Fi proxy settings, and IoT devices through a gateway proxy. All of them land in the same Session, and the AI analysis step processes them together.

The intended user is someone doing black-box protocol work: reverse-engineering a site's API, recovering a mobile app's request signing logic, or auditing a service for leaked tokens and CSRF issues. It is a desktop application, not a library, so the audience is the engineer at a keyboard, not a CI pipeline.

## How the Capture Pipeline Is Wired

The repository layout in the README shows the architecture plainly. Under src/main, capture holds the CDP Fetch interception and JS hook injection, cdp manages the Chrome DevTools Protocol connection, proxy holds the MITM proxy with CA management and certificate issuance, ai holds a two-stage analysis pipeline with prompt templates and LLM routing, mcp holds both an MCP client and a built-in MCP server, db is a better-sqlite3 layer, and session manages session lifecycle.

Two capture channels feed one session. The embedded browser uses CDP Fetch interception to record every HTTP request and response including headers and body. The MITM proxy handles everything outside the browser. Requests are tagged with their origin so you can tell CDP traffic from proxy traffic.

The AI side is explicitly two-phase: Phase 1 filters noise, Phase 2 does the deep analysis, and the model can pull individual request details on demand rather than being handed the whole capture at once. That matters because a session can be large. There are five analysis modes (auto, API reverse engineering, security audit, performance, and JS crypto reverse engineering), streaming output, and follow-up questions after a report is generated.

The JS hook layer is the part worth calling out. It intercepts fetch, XHR, crypto.subtle, CryptoJS and SM2/3/4 calls, and the app can extract crypto-related code fragments out of JavaScript files. That is the mechanism behind the crypto reverse-engineering mode: instead of inferring the algorithm from ciphertext, the hook sees the call site.

## Installing Anything Analyzer and Capturing Your First Request

The README points to GitHub Releases rather than a package registry. Installers are named per platform: Anything-Analyzer-Setup-x.x.x.exe for Windows, Anything-Analyzer-x.x.x-arm64.dmg and Anything-Analyzer-x.x.x-x64.dmg for macOS, and Anything-Analyzer-x.x.x.AppImage for Linux.

If you would rather build from source, the README gives these commands. Note the capitalised WW in the clone URL, which differs from the owner casing used elsewhere in the repository.

```bash
git clone https://github.com/MouseWW/anything-analyzer.git
cd anything-analyzer
pnpm install
pnpm dev        # development mode
pnpm test       # run tests
```

pnpm dev starts the Electron app in development mode. Building a distributable is a separate step, and the README shows the Windows form of it:

```bash
pnpm build && npx electron-builder --win
```

Once the app is open, the README's first-run sequence for a web target is four steps: configure an LLM under Settings then LLM with an API key (OpenAI, Anthropic or any compatible endpoint), create a new Session with a name and target URL, operate the site inside the embedded browser and click Start Capture, then stop capture and click Analyze to pick an analysis mode. The README does not document a rollback for a session once analysis has run.

## Pointing External Traffic at the Proxy

The proxy listens on port 8888 by default. Enabling it is a Settings step, and the README requires installing the CA certificate first. The certificate lives under %APPDATA%/anything-analyzer/certs/ on Windows and ~/Library/Application Support/anything-analyzer/certs/ on macOS, and first-time installation needs administrator rights. The root CA is valid for 10 years and leaf certificates for 825 days, which the README says is to satisfy Apple's requirements.

For a terminal command, the documented form is:

```bash
curl -x http://127.0.0.1:8888 https://api.example.com/data
```

The request should appear in the active session tagged as proxy traffic. The README gives the equivalent configuration for a Python script and for Node.js:

```python
proxies = {"http": "http://127.0.0.1:8888", "https": "http://127.0.0.1:8888"}
requests.get("https://api.example.com/data", proxies=proxies)
```

```bash
HTTP_PROXY=http://127.0.0.1:8888 HTTPS_PROXY=http://127.0.0.1:8888 node app.js
```

For desktop applications, Settings has a one-click option to set the system proxy. For a phone or tablet, the README says to set Wi-Fi HTTP proxy to manual with the computer's IP and port 8888, then open the proxy address in the phone browser to download and install the CA certificate. A session created with an empty URL still receives that external traffic.

## Where the MITM Design Stops

The README is unusually candid in its CA certificate section, and the limits it names are the ones to take seriously. The MITM proxy is read-only capture: it does not modify request or response content. WebSocket traffic is tunnelled, not decrypted. Individual bodies are capped at 1MB, and binary content is skipped automatically.

That combination rules out a set of jobs. If your target protocol runs over WebSocket, the app will show you the upgrade request and then nothing useful about the frames. If you are analysing a binary protocol, a protobuf-heavy service, or anything transferring files larger than 1MB, the body will not be there. And because modification is off the table, you cannot use it to replay a tampered request or test how a server reacts to an altered signature.

The certificate handling is the other boundary. Installing a root CA on a device is a real change to that device's trust store, and on iOS and recent Android versions it can require more than a settings toggle. Anything Analyzer gives you install, uninstall, regenerate and export actions, but the README notes the first install needs admin rights (Windows UAC or macOS password). On a machine you do not control, that alone can be a blocker.

There is also a packaging caveat that has nothing to do with capture: the README warns that macOS auto-update depends on signed and notarised builds, and that GitHub Actions needs CSC_LINK, CSC_KEY_PASSWORD, APPLE_ID, APPLE_APP_SPECIFIC_PASSWORD and APPLE_TEAM_ID configured in repository Secrets or ShipIt cannot install updates. That is a maintainer concern, but it tells you the macOS update path is more fragile than the Windows one.

## Anything Analyzer vs Charles and mitmproxy

The honest comparison is with mitmproxy, because that is the tool most people reach for when they need a scriptable HTTPS proxy.

mitmproxy is a Python program with a console UI, a web UI and a scripting API. You write addons in Python, run them headless, and put the whole thing in CI. Its strength is that interception logic is code you own and version. Its weakness for this use case is that it does not analyse anything for you: you still read the flows.

Anything Analyzer inverts both properties. The proxy is a component inside a GUI, not a standalone process you script, and the value comes from the AI layer summarising what was captured. You get a two-phase pipeline, five analysis modes and follow-up questions out of the box, plus MCP so Claude Desktop or Cursor can call the capture tools directly. You give up headless operation and the ability to write your own interception logic.

Charles sits between the two: a mature commercial GUI proxy with strong mapping and rewriting features. Anything Analyzer's proxy is explicitly read-only, so if rewriting responses is part of your workflow, Charles or mitmproxy is the right tool and Anything Analyzer is not.

The MCP angle is the genuinely different piece. The README describes both directions: an MCP client that connects to external MCP servers over stdio and StreamableHTTP to extend analysis, and a built-in MCP server that exposes capture and analysis as tools for other agents. If your workflow already lives in an agent IDE, that is the reason to pick this over a plain proxy.

## Licence, Maintenance and Upgrade Cost

The README carries an MIT badge linking to a LICENSE file, but the top-level repository listing does not include a LICENSE file. Treat the licence as unverified until that file exists, and read it before you ship anything derived from the source. Nothing here is legal advice; if the distinction matters to your organisation, ask someone qualified.

The last push was on 2026-09-09, and the most recent release listed is v3.6.61 from 2026-08-26. The version in package.json is 3.6.62. Releases have been frequent, with three listed between early August and late August 2026, and the version numbering suggests small increments rather than long cycles.

Upgrade cost is mostly operational rather than code-level, since this is an installed desktop app. Auto-update is built in via electron-updater. The friction is on macOS, where the README ties updates to signed and notarised packages. Building from source needs Node.js 18 or newer, pnpm (package.json pins pnpm@10.24.0), and Visual Studio Build Tools on Windows, which better-sqlite3 makes necessary. The stack is Electron 35, React 19, Ant Design 5, TypeScript 5 and better-sqlite3, so anyone forking it inherits a full Electron toolchain rather than a small script.

## Conclusion

Adopt Anything Analyzer if you reverse-engineer HTTP and HTTPS APIs across browsers, CLI tools and mobile apps and want the captured traffic summarised by an LLM rather than read by hand. Do not adopt it for WebSocket payload inspection, for binary or large-body protocols, or for anything where you cannot install a root CA on the target device. Before committing, verify three things: that the repository has no LICENSE file even though the README badge says MIT, that your chosen LLM endpoint works with the Chat Completions or Responses API the app routes to, and that the MITM proxy's read-only, non-decrypting WebSocket behaviour matches what you actually need to inspect.

## FAQ

### How do I install Anything Analyzer?

Download the installer for your platform from the GitHub Releases page: Anything-Analyzer-Setup-x.x.x.exe for Windows, the arm64 or x64 .dmg for macOS, or the .AppImage for Linux. Building from source instead requires Node.js 18 or newer and pnpm, then pnpm install followed by pnpm dev.

### Does Anything Analyzer decrypt WebSocket traffic?

No. The README states that WebSocket traffic is tunnelled and not decrypted, so the app detects the upgrade request but does not expose the frames. The MITM proxy is also read-only and does not modify requests or responses.

### What are the limits on captured request bodies in Anything Analyzer?

The README documents a 1MB cap on a single body, and binary content is skipped automatically. Larger payloads and binary protocols therefore will not appear in the captured data.

## Sources

- [Issues](https://github.com/Mouseww/anything-analyzer/issues)
- [Mouseww/anything-analyzer on GitHub](https://github.com/Mouseww/anything-analyzer)
- [README](https://github.com/Mouseww/anything-analyzer/blob/main/README.md)
- [Releases](https://github.com/Mouseww/anything-analyzer/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/mouseww-anything-analyzer
