From dce8138463e002fca24175cf96c37fde54b49d2e Mon Sep 17 00:00:00 2001 From: jhuang-tw <77732008+jhuang-tw@users.noreply.github.com> Date: Tue, 18 Aug 2026 00:20:44 -0700 Subject: [PATCH] docs: show explicit MCP host selection on macOS --- docs/platforms/macos.md | 28 ++++++++++++++++++++++------ 1 file changed, 22 insertions(+), 6 deletions(-) diff --git a/docs/platforms/macos.md b/docs/platforms/macos.md index 9ec2ab0..3b598d4 100644 --- a/docs/platforms/macos.md +++ b/docs/platforms/macos.md @@ -45,7 +45,7 @@ python3 -m pipx ensurepath | Ghidra | `brew install ghidra` or `brew install --cask ghidra` | GitHub release ZIP | Formula/cask availability may vary. | | IDA Pro | manual app install | — | Usually under `/Applications/IDA Professional*.app`. | | BurpSuite | `brew install --cask burp-suite` | manual jar / installer | Load `burp-mcp-full` extension manually. | -| jshookmcp | `npx -y @jshookmcp/jshook@0.3.4` | MCP config command | Requires Node/npm/npx. | +| jshookmcp | `npx -y @jshookmcp/jshook@0.3.4` | MCP config command | Requires Node/npm/npx and explicit MCP registration. | | anything-analyzer | project clone + `pnpm install` | custom local service | Register its MCP endpoint. | | nuclei | `brew install nuclei` | GitHub release / Go install | Optional security scanner. | | SecLists | Git clone | — | Usually clone to `~/tools/SecLists`. | @@ -100,6 +100,16 @@ If the service uses a custom port or token, update your Agent client's MCP confi ## MCP setup notes +The core bootstrap is client-neutral by default. It **does not write** `~/.claude/mcp.json` or `~/.codex/config.toml` unless an MCP host is explicitly selected. For MCP capabilities, use one of: + +```bash +--mcp-host=claude +--mcp-host=codex +--mcp-host=both +``` + +Without an explicit host, the bootstrap may prepare the runtime but reports the MCP capability as `registration-required`. Override the explicit adapter paths with `CLAUDE_MCP_CONFIG` or `CODEX_CONFIG_PATH` when needed. + ### BurpSuite MCP Build the extension: @@ -167,12 +177,18 @@ From the repository root, list the same core capability names as the Windows Pow The generic bootstrap is compatible with the system `/bin/bash` shipped by macOS (Bash 3.2); Homebrew Bash is not required. -Install or configure supported capabilities with the generic Bash bootstrap: +Install ordinary capabilities without selecting an Agent client: ```bash /bin/bash skills/scripts/bootstrap-reverse.sh jadx apktool frida -/bin/bash skills/scripts/bootstrap-reverse.sh jshookmcp anything-analyzer -/bin/bash skills/scripts/bootstrap-reverse.sh burpsuite-mcp +``` + +For MCP registration, select the target client explicitly: + +```bash +/bin/bash skills/scripts/bootstrap-reverse.sh jshookmcp --mcp-host=codex +/bin/bash skills/scripts/bootstrap-reverse.sh anything-analyzer --mcp-host=claude +/bin/bash skills/scripts/bootstrap-reverse.sh burpsuite-mcp --mcp-host=both ``` Refresh the local tool index only: @@ -188,7 +204,7 @@ skills/tool-index.md skills/tool-index.json ``` -`bootstrap-reverse.sh` installs/configures supported capabilities where possible on macOS, using Homebrew, `pipx`, `npm`, GitHub releases, and MCP registration. `refresh-tool-index.sh` is detection-only. Manual-only tools such as IDA Pro and BurpSuite still require local app installation and app-specific setup. +`bootstrap-reverse.sh` installs or prepares supported capabilities where possible on macOS using Homebrew, `pipx`, `npm`, and GitHub releases. MCP client registration occurs only when `--mcp-host=...` is explicit. `refresh-tool-index.sh` is detection-only and discovers supported MCP registrations without choosing a default Agent client. Manual-only tools such as IDA Pro and BurpSuite still require local app installation and app-specific setup. ## Validation checklist @@ -211,4 +227,4 @@ bash skills/scripts/refresh-tool-index.sh - GUI app paths vary by edition and version. Do not hard-code IDA or Burp paths unless you verified them locally. - Some security tools are Linux-first. Prefer Homebrew formulae first, then GitHub releases, then source builds. -- iOS analysis may require additional signing, device, and jailbreak-specific setup; keep those steps in a dedicated mobile reverse Skill rather than this generic platform page. +- iOS analysis may require additional signing, device, and jailbreak-specific setup; keep those steps in a dedicated mobile reverse Skill rather than this generic platform page. \ No newline at end of file