Mitm List Apis

List all APIs from mitmproxy traffic capture. Use when user asks to see APIs, endpoints, or wants an overview of captured HTTP traffic for a website or app.

instavm bf00c0b 1.1 KB Updated

File contents

List APIs from Traffic Capture

Analyze the mitmproxy dump (log.txt) and list all APIs for: $ARGUMENTS

Requires: log.txt in the current directory. If it's missing, capture traffic first:

mitmdump --set flow_detail=3 2>&1 | tee log.txt

Instructions

  1. Search log.txt for the target domain/app
  2. Extract unique API endpoints
  3. Group by functionality (auth, user, payment, etc.)

Output Format

For each API found:

  • Method: GET/POST/PUT/DELETE
  • Endpoint: /api/path (skip domain)
  • Input params: Query params or body fields
  • Response fields: Key fields returned (concise)

Grouping Suggestions

  • Authentication (login, register, OTP, token)
  • User Profile (profile, settings, preferences)
  • Transactions (orders, payments, history)
  • Content (products, listings, search)
  • Admin/Internal (if any found)

If no website specified, ask which one to analyze.

instavm/security-skills/tree/main/skills/mitm-list-apis commit bf00c0b48b

Frequently asked questions

npx skillmds@latest add instavm/mitm-list-apis