Reverse-engineering web apps into agent tools
Details
- External ID
- 48847834
- Source
- HN
- Company
- —
- Product
- —
- Website domain
- —
- Launched
- July 9, 2026
- Cohort
- —
- Upvotes
- 96
- Upvotes percentile
- 0.9074074074074074
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hey HN! We built a browser-based agent that runs inside an authenticated web app, watches how the app calls its own APIs, and automatically turns those into agent tools. You can think of it as an auto-generated MCP server that self-updates as the host app changes.The result is a skilled AI assistant that actually integrates deeply with any product (not just chat and RAG) with minimal effort.Check out these short demos below that show the agent in software you're probably familiar with:- Jira: https://demo.frigade.com/hn?skill=jira- Spotify: https://demo.frigade.com/hn?skill=spotify- Hacker News (lol): https://demo.frigade.com/hn?skill=hackernews- Full Demo: https://demo.frigade.com/hn?skill=full-demoAs you can see in the examples, you can do way more (and faster) than what you normally would be able to via point and click. And we never even touched the source code of these products!Why do this?In an ideal world, every application has an MCP server or an easily-digestible API available for AI agents to feed from. In practice, we found that even very modern software tends to have a spider web of confusing APIs and services that AI agents simply cannot use out of the box. Security also becomes a huge issue as applications have different (often homebrewed) standards for how endpoints are secured (JWTs/cookies/mix of both). Finally, having an actual browser agent go in and use the application on behalf of the user (i.e. computer-use), is simply too brittle, slow, and burns a lot of tokens.We took our existing browser agent that’s already trained to use and learn authenticated applications, and added an extra step that automatically turns the app’s authenticated APIs into "recipes". A recipe is a mix of the following:- API endpoint + method- Authentication method (and how to retrieve refresh auth tokens/cookies)- Response schema- Input schema (for POST/PUT)- Human readable description of what the tool doesPutting it all together, these become reusable tools for LLMs, all without writing or maintaining any code. Even if the APIs change our agent figures this out and replaces the recipe for the tool with the updated version.Adding tools to an AI agent becomes super simple this way:- Our agent trains on the app and builds the recipes- The app owner enables discovered tools from our dashboard- The agent can now take actions on the user’s behalf directly inside the application. For instance, saying something like "invite my teammate to my workspace" would securely call the existing API endpoint for inviting users without proxying or relaying through a third party.Of course, there's a ton of edge cases you run into when you try to do this - every application is intrinsically different despite how many "standards" exist. Fun fact: graphql was by far the worst API to work with in standardizing the recipes.Looking forward to your feedback/comments!
Enrichment
- Theme
- browser automation and scraping for AI
- Vertical
- Horizontal
- Function
- Agent / copilot
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Hobby / open-source project
- Normalized one-liner
- convert web apps into ai agent tools
- Manually corrected
- False
Could you build this?
Partial Capturing browser network requests via an extension or Puppeteer is straightforward, but dynamically synthesizing reliable, schema-validated API tool definitions from arbitrary web traffic requires sophisticated heuristics.
What it would actually take: The architecture involves a Chrome extension or Playwright instance that hooks `fetch`/`XMLHttpRequest` to observe network calls, payload structures, and auth headers. The difficult challenge is automatically parsing variable REST/GraphQL traffic, inferring semantic parameters, deduplicating endpoints, and generating valid OpenAPI/MCP tool schemas on the fly. Doing this reliably across diverse authentication schemes and dynamic web frameworks requires specialized web reverse-engineering and advanced LLM tool-calling orchestration.
Discussion
20 comments analyzed.
Competitors mentioned: Intercom (chat widget integration), WebMCP (browser agent APIs), rtrvr.ai/rover (GUI-based agents)
Concerns raised: Terms of service violations from injecting third-party JavaScript, Account bans and legal liability from extracting auth tokens, Authentication bypass and hacking charges risk, Remote attestation in browsers will prevent this approach, Irresponsible without proper business-level support
Feature requests: Support for authenticated sessions behind login walls (JWT), Direct API spec integration as alternative to reverse engineering, Better documentation on legal compliance and ToS adherence
Competitors
Other products that read as similar to this one — 316 launches clear the similarity bar, closest 8 shown.
Attention rank: #44 of 317 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 250 days after the earliest competitor.
- PageAgent, A GUI agent that lives inside your web app · hn · 2026-03-05 · 147 upvotes · similarity 0.54
- BrowserAct · ph · 2026-06-25 · 561 upvotes · similarity 0.53
- peerd · hn · 2026-06-23 · 75 upvotes · similarity 0.53
- Usable Browser Agent · ph · 2026-09-08 · 2 upvotes · similarity 0.52
- Rtrvr.ai · hn · 2025-11-12 · 6 upvotes · similarity 0.51
- Integuru · hn · 2026-05-29 · 7 upvotes · similarity 0.50
- The agent that builds and operates its own SaaS tools · hn · 2026-06-09 · 11 upvotes · similarity 0.49
- Mastra 1.0, open-source JavaScript agent framework from the Gatsby devs · hn · 2026-01-20 · 213 upvotes · similarity 0.47
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.