mitmproxy
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing administrative commands to configure system networking and certificate stores. * Evidence: Use of
iptablesfor NAT redirection andecho 1 > /proc/sys/net/ipv4/ip_forwardfor IP forwarding inSKILL.md. * Evidence: Use ofupdate-ca-certificatesfor system-wide trust store modification inreferences/addons.md. - [PRIVILEGE_ESCALATION]: The documented procedures require elevated privileges to manipulate the operating system's network stack and security trust settings. * Evidence: Commands involving
iptablesand system-wide certificate installation (/usr/local/share/ca-certificates/) typically require root or sudo access. * Evidence: Enabling IP forwarding via/proc/sys/net/is a restricted system-level operation. - [CREDENTIALS_UNSAFE]: The skill includes Python addons designed to monitor network traffic for sensitive patterns and log them to local files. * Evidence: The
CredLoggeraddon inreferences/addons.mduses regular expressions to extract potential credentials (e.g., password, token, secret, api key) from POST requests and store them incredentials.txt. * Evidence: Examples inSKILL.mddemonstrate logging entire POST request bodies toposts.txt. - [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and acting upon untrusted data from external network communications, creating an attack surface for indirect injection. * Ingestion points: Intercepts network flows via mitmproxy hooks as seen in
SKILL.mdandreferences/addons.md(e.g.,flow.request.get_text(),flow.response.json()). * Boundary markers: The provided addon scripts process raw network data directly without specific boundary delimiters or isolation in the code snippets. * Capability inventory: The skill demonstrates capabilities to write to the filesystem, modify network traffic in transit (e.g., replacing role or admin fields), and replay client requests viareplay.client. * Sanitization: The reference scripts do not implement sanitization or validation of the intercepted network data before it is processed, logged, or re-injected into the proxy stream.
Audit Metadata