mitmproxy
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is coherent with its stated purpose and uses official mitmproxy tooling, but the purpose itself gives an AI agent offensive traffic-interception and auth-bypass capabilities. There is no strong evidence of malware or credential exfiltration to third-party servers, yet the network manipulation and capture scope is high-risk and disproportionate for general use.
The material contains explicit sensitive-data collection through CredLogger and active response/request manipulation through the JSON modifier and fuzzing addon. These behaviors may be legitimate in an authorized security-testing environment, but credential logging to an unprotected plaintext file and forced admin privilege changes create substantial security and privacy risk. No evidence of covert network exfiltration, persistence, or obfuscated malware is present.