Back to Skills

ghost-proxy

Starts and controls the reaper MITM proxy to capture, inspect, search, and replay HTTP/HTTPS traffic between clients and servers. Capabilities include starting/stopping the proxy scoped to specific domains, viewing captured request/response logs, searching traffic by method/path/status/host, and inspecting full raw HTTP entries for security analysis. Use when the user asks to "start the proxy", "capture traffic", "intercept requests", "inspect HTTP traffic", "search captured requests", or "view

393stars26forksUpdated 6/19/2026

Security Assessment

Low Risk(75/100)

Detected risks:

Remote Code Execution([SKILL.md] curl -sfL https://raw.githubusercontent.com/ghostsecurity/reaper/main/scripts/install.sh | bash)
Security Score75/100

About ghost-proxy

The ghost-proxy skill provides control over the Reaper MITM (Man-in-the-Middle) proxy, a CLI-based tool designed for application security testing. It intercepts and logs HTTP/HTTPS traffic flowing between clients and servers, enabling security professionals and developers to capture, inspect, and analyze network communications in real-time. The proxy operates with domain-scoped interception, meaning you can precisely target specific domains or hosts while allowing other traffic to pass through transparently.

Reaper's main capabilities include starting and stopping the proxy server in both foreground and daemon modes, capturing all HTTP/HTTPS request-response pairs that match configured domain or host filters, and maintaining a searchable log of intercepted traffic. The tool supports flexible filtering with wildcard patterns for hosts and paths, status code filtering, and HTTP method-based searches. Each captured entry can be inspected individually to view full raw HTTP request and response data, making it invaluable for debugging API integrations, validating security headers, and identifying potential vulnerabilities in web traffic.

This skill is particularly useful for security researchers conducting penetration tests, developers debugging API integrations, QA engineers validating HTTP behavior, and DevOps teams troubleshooting service-to-service communications. Common use cases include intercepting traffic from mobile apps or desktop clients to analyze authentication flows, capturing API requests to understand third-party integrations, replaying requests for security testing, and inspecting encrypted HTTPS traffic that would otherwise be opaque. The proxy generates its own CA certificate for TLS interception, allowing it to decrypt and log HTTPS traffic while maintaining the encrypted channel between client and server.

FAQ

How do I install the Reaper proxy before using this skill?

Run the installation script: `curl -sfL https://raw.githubusercontent.com/ghostsecurity/reaper/main/scripts/install.sh | bash`. This installs the binary to `~/.ghost/bin/reaper`. You can add `~/.ghost/bin` to your PATH or invoke it with the full path.

Why do I need to use -k or verify=False when making requests through the proxy?

Reaper generates its own CA certificate at startup to perform MITM TLS interception. Your HTTP client will not trust this certificate by default, so you need to disable certificate verification with flags like `-k` (curl) or `verify=False` (Python requests) to allow the connection.

What's the difference between --domains and --hosts flags?

--domains performs suffix matching, so `example.com` will capture traffic to `example.com`, `api.example.com`, and any subdomain. --hosts requires exact matching, so `api.example.com` will only capture traffic to that specific hostname.

Does the proxy capture all traffic or only specific domains?

The proxy only logs traffic matching the domains or hosts you specify with --domains or --hosts flags. All other traffic passes through transparently without being captured. This scoping prevents log pollution and focuses analysis on target systems.

Can I run the proxy in the background?

Yes, use the `-d` flag when starting: `reaper start --domains example.com -d`. This runs the proxy as a daemon. Use `reaper stop` to terminate the background process.

Install ghost-proxy

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill