proxyman-https-capture
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill uses tools to perform system-level changes such as setting the system proxy (set_system_proxy), installing root certificates (install_certificate), and utilizing adb root or Magisk for Android emulators. These capabilities are central to the skill's purpose but grant significant control over security configurations.
- [DYNAMIC_EXECUTION]: The skill utilizes tools like inject_terminal and inject_electron to modify the execution environment of other applications.
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from captured network traffic and documentation citations. 1. Ingestion points: Network flow details (filter_flows, get_flow_detail) and external citations (answer_setup_question). 2. Boundary markers (present/absent): Absent. 3. Capability inventory: System configuration (set_system_proxy, install_certificate) and environment injection (inject_terminal, inject_electron). 4. Sanitization (present/absent): Absent.
Audit Metadata