Charles Proxy MCP 服务器,checkpoint 时间线 + 增量收割,专为 AI agent 逆向分析设计
Charles MCP server has 17 tools with mixed quality. Naming is generally verb-based and clear (get_*, filter_*, list_*, etc.), following conventions well. However, descriptions are inconsistent: many are in Chinese and overly technical, lacking the 10-1024 character sweet spot and clear WHEN/WHY guidance. Schemas are present but sparse, most tools have minimal parameter descriptions (e.g., 'Keyword to search for' is generic; no format/length constraints). Output schemas are not documented. Error handling is absent from tool definitions. No tool annotations (readOnlyHint, destructiveHint). Critical issue: descriptions like 'harvest_data' are 200+ chars of technical jargon without actionable guidance for LLM selection. Parameter descriptions lack constraints (e.g., 'limit' has no min/max bounds). No security considerations documented despite tools handling sensitive proxy data.
分析当前 CACHE 中所有条目的 body 信息熵,识别加密/混淆内容。
开始一个命名业务抓包会话。 创建一个时间重置点;随后触发业务操作并调用 harvest_data()。默认不会清空 Charles。 name 应描述业务动作,例如"登录失败重试"。
结束当前命名抓包会话,并返回其覆盖的 checkpoint 范围。
在当前 CACHE 中按 host 过滤条目,支持前缀匹配和正则表达式。
在当前 CACHE 中按关键词过滤条目,返回命中的条目及其命中位置。
在当前 CACHE 中按 HTTP 方法过滤条目。
在当前 CACHE 中按 HTTP 状态码过滤条目。
Descriptions are overly technical and in Chinese; lack actionable WHEN/WHY guidance for LLM selection. E.g., 'harvest_data' description is 200+ chars of checkpoint/timeline jargon without explaining when to call it vs. other capture tools.
Parameter descriptions lack constraints. 'limit' appears in 5 tools with no min/max bounds documented. 'threshold' in analyze_entropy has no range guidance. LLMs will pass arbitrary values.
No output schemas documented. Tools return complex structures (entries, checkpoints, metadata) but LLMs cannot see what fields to expect. Breaks downstream tool chaining.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 49 | 2026-07-28+ | v2 |
返回当前 CACHE 的元数据和统计信息。
返回当前 Charles 连接模式与代理状态。 managed_headless 模式由 MCP 启动并独占一个本机 Charles 实例;external 模式连接用户自行启动的 Charles。
获取指定条目的完整原始数据(请求/响应头、body 等)。
从 Charles 同步增量流量,并在时间线上创建一个新 checkpoint。 【fresh_start=False】(默认) 取上次 harvest 之后产生的新条目,写入 ARCHIVE,创建 checkpoint。 首次调用时加载 session 全部流量。 【fresh_start=True】 在时间线上插一个"重置点",不加载任何条目。 之后的 harvest_data() 只返回此刻之后的新流量。 典型用法:切换分析目标前调用一次。 默认不会修改 Charles session。clear_charles=True 时才会在归档成功后清空 session 并重启录制。 每次调用都会将新条目存入 ARCHIVE、切换 CACHE,并使关键词授权失效。
列出命名抓包会话及其 checkpoint 覆盖范围。
列出时间线上的所有 checkpoint,包括 live 和 recording 来源。
加载命名抓包会话中的所有条目,供过滤与分析工具在整个业务窗口内工作。
从本地 .chlsj 文件加载历史录包,创建 checkpoint 并切换 CACHE。
激活或关闭 Charles 弱网模拟预设。
切换到指定 checkpoint,更新 CACHE 供后续过滤/分析工具使用。
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Tools marked as WRITE (harvest_data, begin_capture, set_throttling) lack explicit destructive hints. LLMs cannot distinguish safe reads from risky writes.
No error handling guidance in tool definitions. No recovery hints, retryability classification, or actionable error messages. E.g., if Charles is unreachable, LLM gets no guidance on what to do next.