webapp-re
Developer tool, October 2026. Code on GitHub.
webapp-re is a Claude Code plugin that finds the private HTTP API behind a web app you're signed into and turns what it finds into a small automation program plus a plugin of its own, so the site gets its own slash commands. It works from the session in your own signed-in browser rather than a password.
The stages
Each stage is its own skill and reads what the one before it wrote from a fixed path, so you never pass files between them. reverse takes a site and a goal phrased as something you'd do, captures the traffic, narrows it to the one call that does the job, replays it, and records the result in a per-site knowledge base. scope runs that method across the whole site, read-only. plan turns the inventory into commands without sending any requests. engineer builds the program and the site plugin and checks every command against the live site. optimize audits what was built and changes nothing until you've accepted its findings.
Staying polite to the site
The generated program keeps one request in flight and waits at least 3 seconds between requests to the same origin, with some jitter. It retries only transport errors, and a 429, a challenge page or a checkpoint stops the whole client rather than the one call. Cookies come from a file you fill from your own browser, kept at mode 600 and redacted in every log. A call that would change data on the site waits for your approval.
What a run leaves behind
Every site gets its own workspace holding the scope and plan, one Markdown file per verified endpoint, an OpenAPI spec rendered from those endpoints, the program, and the generated plugin. The knowledge base is plain Markdown, and a goal whose endpoint was verified and replayed in the last 30 days skips the capture and goes straight to reproducing the call. Each workspace is its own git repository, and the plugin, the captures and the cookie file are gitignored because they're tied to your account.
Stack
Every script is a uv inline script, so uv fetches Python 3.11 or newer and the one dependency, websockets for the Chrome DevTools Protocol capture, on its own. The browser is driven through the Claude in Chrome extension or over CDP on a separate profile you sign into by hand. The repo has CI and a test suite for the menu builder, and it vendors two MIT-licensed skills with their own licenses.
See the code on GitHub, or go back to mahfujmustafa.dev and the rest of my projects.