KRYPTHEON

Your assistant says done. It never opened the app.

MIT licenceNode 20.6+Runs locally
Index 01 — The loopStep 01
01

One flow, recorded once, in the browser you already have open.

01 — Record

It opens your app in a browser window - local, or a deployed address like a Lovable URL. Click through one flow and close it. It writes a real Playwright spec you can open and read.

02 — Change

Let the assistant work. A refactor, a new feature, a fix - whatever you were going to do anyway.

03 — Check

It replays the flow in a real browser against your app and says in plain English what broke.

04 — Accept

When the change was the point, take the new state as the baseline and carry on from there.

It renders.
The flow
underneath is dead.

A page that loads is not a page that works

Index 02 — The reportStep 03

What you get when something breaks

No stack trace and no screenshot to squint at. Three facts, in the order you would ask for them.

01

The step, not the run

A failure names the step it died on and quotes what it was looking for, instead of handing you a stack trace and a screenshot.

02

When it last worked

Every pass is written to a history file, so a failure can say the flow was fine eight minutes ago - which tells you it was the last change, not the one before.

03

What else moved

Console errors and failed requests are compared against the last good run, so you are shown what is new rather than everything the page prints.

Index 03 — In your repoStep 04

Four files, all of them yours

Everything it makes is a readable file in your project. Delete any of them and it starts again from what is left.

tests/*.spec.js

The recording, as a plain Playwright spec

kryptheon-history.jsonl

One line per run, so a failure knows when it last passed

Baselines

The URL and title a passing flow landed on

CLAUDE.md · AGENTS.md

The rule that makes an assistant check before it says done

Index 04 — Your databasekryptheon-night

Your database, attacked. On a copy.

It copies the shape of your Supabase or Postgres database - tables, columns, the rules about who may see what - never a row. It attacks the copy with four questions, tells you in plain English what got through, and deletes it.

ImpersonationCan a stranger, or another customer, read this table?Read
TamperingCan a stranger add, change or delete your data? Every write is rolled back.Write
CollisionCan the same thing exist twice - two accounts for one email, two orders with one number?Race
InterruptionCan a half-finished write survive - a row pointing at something that was never saved?Orphan

Every report ends with what was not tested, and why. Finding nothing is never called safe - it is called these attacks, this time, lost.

npx kryptheon-night
Index 05 — In your AI toolkryptheon-mcp

Your assistant checks its own work

Add the MCP server and your assistant gets all of it as tools: record a flow with you, check it after every change, scan the database. It is told not to call a change done until the check passes.

00

Once, before anything else: install Node.js, the LTS version. Then pick the tool you use.

From Cursor's own docs

Cursor

Add to Cursor →or by hand, below
  1. 1Click Add to Cursor. Cursor asks you to confirm - say yes.
  2. 2Or by hand: paste the config into mcp.json in the .cursor folder of your home folder.
~/.cursor/mcp.json
{
  "mcpServers": {
    "kryptheon": {
      "command": "npx",
      "args": [
        "-y",
        "kryptheon-mcp"
      ]
    }
  }
}
On Windows, and it says it cannot start npx

Replace the command line with these two:

the kryptheon entry
"command": "cmd",
"args": ["/c", "npx", "-y", "kryptheon-mcp"]
Scan your database too

Add your Supabase connection string next to "args". Never paste it into the chat - that puts the password to your whole database in a transcript.

the kryptheon entry
"env": { "KN_DATABASE_URL": "postgresql://..." }
Then just ask

“Check my app.”

Or: “record my app at https://my-app.lovable.app”. Lovable, Bolt, v0, ChatGPT and Claude.ai in the browser only accept hosted servers, so Kryptheon cannot be added to them yet.

Index 06 — What it costsStep 02

The whole tariff

There is no paid tier and no plan to compare against. This is the entire list.

The toolOne dev dependency. It brings its own browser and needs nothing else.Free
Database scanIts own command. The connection string stays on your machine and is never printed back.Free
AI tool plug-inAn MCP server with no dependencies of its own. The first time, it starts in about four seconds.Free
AccountThere is nothing to sign up for and no key to paste anywhere.None
Data sentEverything runs on your machine. There is no server on our side to send anything to.None
NodeThe one version requirement. Everything else is already on your machine.20.6+
LicenceThe source is on GitHub and the spec it writes belongs to you.MIT
Index 07 — QuestionsStep 03

The things people ask first

How is this different from writing Playwright tests myself?

It is Playwright underneath, and the file it writes is an ordinary spec you can open and edit. What it adds is the recording, the baseline it keeps after a pass, and a failure report written in plain English instead of a stack trace.

Does anything leave my machine?

No. It records in a browser on your computer, replays against your local app, and writes its history to a file in your project. There is no account, no API key and no server to talk to.

What happens to passwords I type while recording?

A value typed into a password field is never written into the spec. It is replaced with an environment variable reference and the run tells you which variable to set in your .env file, which stays out of git.

I built my app in Lovable. I only have a web address.

That is enough. Open a terminal and run npx kryptheon@latest record with your app's address. It sets up a folder for the recordings itself - from your home folder it makes one called kryptheon-tests - and tells you where it is. After each change, run npx kryptheon check from that folder.

Can my AI assistant run it?

That is the point. Add the MCP server and your assistant gets the tools directly: it records with you, checks after every change, and is told not to call a change done until the check passes. Without MCP, npx kryptheon setup-ai writes the same rule into CLAUDE.md, AGENTS.md and .cursorrules, and npx kryptheon check --quiet keeps the output short.

Does the database scan touch my data?

No. It reads the shape of your database - table names, columns and the rules about who may see what - rebuilds that shape in a throwaway schema, attacks the copy, and deletes it afterwards - also when the scan fails partway. None of your rows is read, changed or copied.

Which databases can it scan?

Postgres, including any Supabase project you own. It needs the connection string, which Supabase shows under Project Settings, Database. An app on Lovable Cloud - Lovable's built-in backend - does not hand one out, so the scan cannot reach it yet.

It found nothing. Am I safe?

It will never say so. Nothing found means these attacks, this time, lost. Every report ends with what was not tested and why, because an attack that never ran looks exactly like one that was refused.

What if I have not recorded anything yet?

It says so and exits zero. A fresh project with no recordings is not a failure, and reporting it as one only sends an assistant off trying to fix something that is not broken.

Free. Local. Nothing leaves your machine.

View on GitHub