AICryptoProxy — security grade SAFE, quality 57/100

Security audit verdict: SAFE · quality 57/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by hzhsec · MCP Server · ★ 51

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is AICryptoProxy safe to install? View the security audit →

About AICryptoProxy

AICryptoProxy AI 驱动的 Web 加密流量渗透测试自动化代理框架 概述 AICryptoProxy 是一个基于 Claude Code + MCP 的智能渗透测试框架,专为解决前端加密 Web 应用的流量加解密问题而设计。 通过 Claude Code 的 MCP 技能系统,框架能够在几十秒内自动完成传统需要数小时的 JS 逆向分析工作,生成可直接使用的 mitmproxy 加解密代理,配合 Burp Suite 实现无缝的明文操作体验。 核心理念 解决的问题 工作模式 AICryptoProxy 提供两种互补的工作模式,由 Claude Code 的 Skill 自动完成: 模式 A:Direct Crypto(直接加解密) skill:mitmproxy 适用于标准算法、Key 固定的场景。 浏览器 → mitmproxy(:8082)[自动解密] → Burp[:8080] → mitmproxy(:8083)[自动加密] → 服务器 ↑ ↑ ↑ ↑ AI 分析 JS 加密算法 操作明文请求 Burp 修改 AI 生成 Python 加密代码 提取 Key 和 IV 不需要改重放

Quick Facts

Stars51
Forks6
LanguagePython
CategoryMCP Server
Quality Score56.7325244417108/100
Open Issues1
Last Updated2026-06-02
Created2026-05-06
Platformsbrowser, claude-code, mcp, python
Est. Tokens~4k

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is AICryptoProxy?

AICryptoProxy is AICryptoProxy 是一个基于 Claude Code(https://claude.ai/code) + MCP(https://docs.claude.ai) 的智能渗透测试框架,专为解决前端加密 Web 应用的流量加解密问题而设计。. It is categorized as a MCP Server with 51 GitHub stars.

What programming language is AICryptoProxy written in?

AICryptoProxy is primarily written in Python.

How do I install or use AICryptoProxy?

You can find installation instructions and usage details in the AICryptoProxy GitHub repository at github.com/hzhsec/AICryptoProxy. The project has 51 stars and 6 forks, indicating an active community.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools