caido

Analyze and replay HTTP traffic through the Caido proxy with JSON output.

Updated Mar 29, 2026
One-click install
npx skills add https://github.com/filipnyquist/caidos --skill caido
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: caido
Source: https://github.com/filipnyquist/caidos/tree/main/.claude/skills/caido
Command: npx skills add https://github.com/filipnyquist/caidos --skill caido

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

The Caido CLI provides a focused way to analyze HTTP traffic, replay requests, and manage security findings using JSON output, enabling automation and AI-assisted analysis.

Core Features & Use Cases

  • Browse traffic (recent, get by ID, search with HTTPQL) to understand target behavior.
  • Replay and modify requests to test endpoints and verify defenses.
  • Manage findings and intercept controls to streamline security workflows.

Quick Start

Install the Caido CLI, ensure a Caido instance is running, and configure your PAT to begin analyzing traffic.

Frequently Asked Questions about caido

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I replay HTTP traffic requests to test endpoint behavior?

You can replay HTTP traffic requests by interfacing with the Caido proxy to resend and modify captured data. This functionality allows you to test endpoints and verify security defenses within your end-to-end workflows.

How do I search HTTP traffic history using HTTPQL?

You can search HTTP traffic history using HTTPQL by querying the Caido proxy. This allows you to browse recent traffic, retrieve specific requests by ID, and analyze target behavior effectively.

Can I manage security findings directly from HTTP proxy traffic?

Yes, you can manage security findings directly from HTTP proxy traffic using the Caido interface. It enables you to control interception, manage findings, and streamline security workflows by outputting results as JSON.

Do I need a running Caido instance to analyze HTTP traffic?

Yes, you need a running Caido instance and a configured Personal Access Token (PAT) to analyze HTTP traffic. The Skill interfaces with the proxy to browse traffic, replay requests, and manage findings.

What is the best way to automate security findings management for HTTP traffic?

The best way to automate security findings management for HTTP traffic is by using the Caido proxy CLI. It provides JSON output for findings and interception controls, enabling AI-assisted analysis and streamlined security workflows.

Does the Caido proxy Skill support loading custom references for traffic analysis?

Yes, the Caido proxy Skill supports loading custom references for traffic analysis. It includes reference components to provide guidance during the HTTP traffic replay and security findings management process.