Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Reverse-engineering web apps into agent tools

Details

External ID
48847834
Source
HN
Company
—
Product
—
Website domain
—
Launched
July 9, 2026
Cohort
—
Upvotes
96
Upvotes percentile
0.9074074074074074
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Hey HN! We built a browser-based agent that runs inside an authenticated web app, watches how the app calls its own APIs, and automatically turns those into agent tools. You can think of it as an auto-generated MCP server that self-updates as the host app changes.The result is a skilled AI assistant that actually integrates deeply with any product (not just chat and RAG) with minimal effort.Check out these short demos below that show the agent in software you're probably familiar with:- Jira: https://demo.frigade.com/hn?skill=jira- Spotify: https://demo.frigade.com/hn?skill=spotify- Hacker News (lol): https://demo.frigade.com/hn?skill=hackernews- Full Demo: https://demo.frigade.com/hn?skill=full-demoAs you can see in the examples, you can do way more (and faster) than what you normally would be able to via point and click. And we never even touched the source code of these products!Why do this?In an ideal world, every application has an MCP server or an easily-digestible API available for AI agents to feed from. In practice, we found that even very modern software tends to have a spider web of confusing APIs and services that AI agents simply cannot use out of the box. Security also becomes a huge issue as applications have different (often homebrewed) standards for how endpoints are secured (JWTs/cookies/mix of both). Finally, having an actual browser agent go in and use the application on behalf of the user (i.e. computer-use), is simply too brittle, slow, and burns a lot of tokens.We took our existing browser agent that’s already trained to use and learn authenticated applications, and added an extra step that automatically turns the app’s authenticated APIs into "recipes". A recipe is a mix of the following:- API endpoint + method- Authentication method (and how to retrieve refresh auth tokens/cookies)- Response schema- Input schema (for POST/PUT)- Human readable description of what the tool doesPutting it all together, these become reusable tools for LLMs, all without writing or maintaining any code. Even if the APIs change our agent figures this out and replaces the recipe for the tool with the updated version.Adding tools to an AI agent becomes super simple this way:- Our agent trains on the app and builds the recipes- The app owner enables discovered tools from our dashboard- The agent can now take actions on the user’s behalf directly inside the application. For instance, saying something like "invite my teammate to my workspace" would securely call the existing API endpoint for inviting users without proxying or relaying through a third party.Of course, there's a ton of edge cases you run into when you try to do this - every application is intrinsically different despite how many "standards" exist. Fun fact: graphql was by far the worst API to work with in standardizing the recipes.Looking forward to your feedback/comments!

Enrichment

Theme
browser automation and scraping for AI
Vertical
Horizontal
Function
Agent / copilot
Audience
Developer
AI stance
AI-native
Project type
Hobby / open-source project
Normalized one-liner
convert web apps into ai agent tools
Manually corrected
False

Could you build this?

Partial Capturing browser network requests via an extension or Puppeteer is straightforward, but dynamically synthesizing reliable, schema-validated API tool definitions from arbitrary web traffic requires sophisticated heuristics.

What it would actually take: The architecture involves a Chrome extension or Playwright instance that hooks `fetch`/`XMLHttpRequest` to observe network calls, payload structures, and auth headers. The difficult challenge is automatically parsing variable REST/GraphQL traffic, inferring semantic parameters, deduplicating endpoints, and generating valid OpenAPI/MCP tool schemas on the fly. Doing this reliably across diverse authentication schemes and dynamic web frameworks requires specialized web reverse-engineering and advanced LLM tool-calling orchestration.

Discussion

20 comments analyzed.

Competitors mentioned: Intercom (chat widget integration), WebMCP (browser agent APIs), rtrvr.ai/rover (GUI-based agents)

Concerns raised: Terms of service violations from injecting third-party JavaScript, Account bans and legal liability from extracting auth tokens, Authentication bypass and hacking charges risk, Remote attestation in browsers will prevent this approach, Irresponsible without proper business-level support

Feature requests: Support for authenticated sessions behind login walls (JWT), Direct API spec integration as alternative to reverse engineering, Better documentation on legal compliance and ToS adherence

Competitors

Other products that read as similar to this one — 316 launches clear the similarity bar, closest 8 shown.

Attention rank: #44 of 317 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 250 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a agent / copilot tool for Agriculture yet.