dev-mitm-proxy
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
- Private Key Management: The documentation references a static CA private key file (
capsem-ca.key) that is compiled into the core components to facilitate TLS termination. While the documentation notes this is intended for use within a sandboxed guest VM, the inclusion of private keys in source code or binary distributions is a security consideration that warrants review of the associated key management practices. - Indirect Prompt Injection Surface: The proxy is designed to intercept and parse streaming traffic from various AI provider APIs (e.g., Anthropic, Google, OpenAI) via the modules in
crates/capsem-core/src/net/ai_traffic/. Although the system uses a structured pipeline with boundary markers likeSecurityEventand performs ledger materialization to sanitize output, the ingestion of untrusted external content represents a potential vulnerability surface for indirect prompt injection or parsing-related issues. - System Configuration and Persistence: The setup process involves modifying the guest virtual machine's root filesystem to include the tool's Certificate Authority (CA) through system utilities like
update-ca-certificates. This modification ensures the proxy can intercept TLS traffic within the guest environment, creating a persistent configuration change in the system's trust store. - Command and Script Execution: The documentation outlines testing and setup procedures that utilize system-level commands (e.g.,
iptables) and local utility scripts (e.g.,check_session.py). These operations are consistent with the tool's purpose as a network debugging layer but require appropriate execution privileges and should be confined to the intended testing environments.
Audit Metadata