npx skills add ...
npx skills add ghostsecurity/skills --skill ghost-proxy
Starts and controls the reaper MITM proxy to capture, inspect, search, and replay HTTP/HTTPS traffic between clients and servers. Capabilities include starting/stopping the proxy scoped to specific domains, viewing captured request/response logs, searching traffic by method/path/status/host, and inspecting full raw HTTP entries for security analysis. Use when the user asks to "start the proxy", "capture traffic", "intercept requests", "inspect HTTP traffic", "search captured requests", or "view request/response".
npx skills add ghostsecurity/skills --skill ghost-proxy
Reaper is a CLI-based MITM HTTPS proxy for application security testing. It intercepts, logs, and allows inspection of HTTP/HTTPS traffic flowing through it. Use it to capture live request/response pairs for security validation.
Before using any reaper command, make sure the latest version of the binary is installed:
All reaper commands in this document should be invoked as ~/.ghost/bin/reaper unless ~/.ghost/bin is on PATH.
| Command | Purpose |
|---|---|
reaper start --domains example.com | Start proxy (foreground) |
reaper start --domains example.com -d | Start proxy (daemon) |
reaper logs | Show recent captured entries |
reaper search --method POST --path /api/* | Search captured traffic |
reaper get <id> | Show full request + response |
reaper req <id> | Show raw HTTP request only |
reaper res <id> | Show raw HTTP response only |
reaper stop | Stop the daemon |
Start reaper scoped to the target domain(s). At least one --domains or --hosts flag is required.
Scope behavior:
--domains: Suffix match. example.com matches example.com, api.example.com, sub.api.example.com--hosts: Exact match. api.example.com matches only api.example.comConfigure the HTTP client to use the proxy. The default listen address is localhost:8443.
The -k / verify=False flag is needed because reaper generates its own CA certificate at startup for MITM TLS interception.
Output columns: ID, METHOD, HOST, PATH, STATUS, MS, REQ (request body size), RES (response body size).
Output is raw HTTP/1.1 format including headers and body, suitable for analysis or replay.
When used with the validate skill (may need to collaborate with the user to setup the test environment):
reaper logs — at least one entry should appear after routing a test request through the proxyreaper get <id> to capture the full request/response as evidenceAll data is stored in ~/.reaper/:
reaper.db - SQLite database with captured entriesreaper.sock - Unix socket for CLI-to-daemon IPCreaper.pid - Daemon process IDThe CA certificate is generated fresh in memory on each start and is not persisted.