http-toolkit-intercept

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard CLI utilities including pkill, curl, and xvfb-run to manage the lifecycle of the HTTP Toolkit server and verify its availability on the local loopback interface (127.0.0.1).
  • [DATA_EXFILTRATION]: Instructions direct the agent to redirect program output to local temporary files (e.g., /tmp/session-stdout.log) to facilitate manual inspection and cross-referencing with network traffic logs.
  • [PROMPT_INJECTION]: No malicious injection patterns, behavioral overrides, or safety bypass instructions were detected. The skill maintains a consistent focus on its stated purpose of network debugging.
  • [REMOTE_CODE_EXECUTION]: No remote scripts are downloaded or executed. The skill references well-known development tools and standard runtime environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 10:34 PM