proxyman-https-capture

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill uses tools to perform system-level changes such as setting the system proxy (set_system_proxy), installing root certificates (install_certificate), and utilizing adb root or Magisk for Android emulators. These capabilities are central to the skill's purpose but grant significant control over security configurations.
  • [DYNAMIC_EXECUTION]: The skill utilizes tools like inject_terminal and inject_electron to modify the execution environment of other applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from captured network traffic and documentation citations. 1. Ingestion points: Network flow details (filter_flows, get_flow_detail) and external citations (answer_setup_question). 2. Boundary markers (present/absent): Absent. 3. Capability inventory: System configuration (set_system_proxy, install_certificate) and environment injection (inject_terminal, inject_electron). 4. Sanitization (present/absent): Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 01:44 PM
Security Audit — agent-trust-hub — proxyman-https-capture