skills/aeondave/malskill/mitmproxy/Gen Agent Trust Hub

mitmproxy

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for executing administrative commands to configure system networking and certificate stores. * Evidence: Use of iptables for NAT redirection and echo 1 > /proc/sys/net/ipv4/ip_forward for IP forwarding in SKILL.md. * Evidence: Use of update-ca-certificates for system-wide trust store modification in references/addons.md.
  • [PRIVILEGE_ESCALATION]: The documented procedures require elevated privileges to manipulate the operating system's network stack and security trust settings. * Evidence: Commands involving iptables and system-wide certificate installation (/usr/local/share/ca-certificates/) typically require root or sudo access. * Evidence: Enabling IP forwarding via /proc/sys/net/ is a restricted system-level operation.
  • [CREDENTIALS_UNSAFE]: The skill includes Python addons designed to monitor network traffic for sensitive patterns and log them to local files. * Evidence: The CredLogger addon in references/addons.md uses regular expressions to extract potential credentials (e.g., password, token, secret, api key) from POST requests and store them in credentials.txt. * Evidence: Examples in SKILL.md demonstrate logging entire POST request bodies to posts.txt.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and acting upon untrusted data from external network communications, creating an attack surface for indirect injection. * Ingestion points: Intercepts network flows via mitmproxy hooks as seen in SKILL.md and references/addons.md (e.g., flow.request.get_text(), flow.response.json()). * Boundary markers: The provided addon scripts process raw network data directly without specific boundary delimiters or isolation in the code snippets. * Capability inventory: The skill demonstrates capabilities to write to the filesystem, modify network traffic in transit (e.g., replacing role or admin fields), and replay client requests via replay.client. * Sanitization: The reference scripts do not implement sanitization or validation of the intercepted network data before it is processed, logged, or re-injected into the proxy stream.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:57 AM
Security Audit — agent-trust-hub — mitmproxy