Terminal-first HTTP proxy with MCP-based AI integration
gori, developed by Hahwul, is a terminal-based HTTP intercepting proxy for security assessment and pentesting workflows. It captures, edits, and replays HTTP/1.1, HTTP/2, WebSocket, gRPC, and SSE flows while exposing a Model Context Protocol server so AI agents can interact with live traffic for analysis. The tool includes a keyboard-driven TUI, TLS passthrough, protocol downgrade detection, fuzzing and replay utilities, and automated configuration for MCP clients. It targets penetration testers, bug bounty hunters, and security researchers who require a fast, terminal-centric AI-security bridge.
Gori maps to hands-on inspection and automated attack pipelines
The tool supports manual traffic inspection through a keyboard-driven terminal interface and scripted execution via its automation commands. Users can capture, modify, replay, and fuzz network flows to exercise application logic and expose protocol weaknesses. The bundled scanning and replay utilities let analysts run repeatable scenarios, and the "gori run" automation mode integrates that activity into scripted pipelines for continuous testing or repeatable pentest tasks.
AI-assisted findings are possible but need analyst validation
By running an MCP server, the tool allows AI clients to access captured traffic and drive analysis workflows; automated configuration helpers target clients such as Claude Desktop and Claude Code. Because the tool exposes raw flows to external agents, any AI-generated vulnerability findings require independent verification by a human analyst before remediation or reporting. The tool enables agent-driven triage but does not replace manual confirmation of high-stakes results.
Installation, platform fit, and developer provenance suit security engineers
The tool runs on macOS and Linux and is written in the Crystal language; installation options include a quick-install script, Homebrew, the AUR, Nix, or building from source. Use of an MCP-compliant client is required to exercise AI features. The developer is known for offensive security projects such as Dalfox and OWASP Noir, which positions the tool within a lineage of attacker-focused open-source utilities and community-oriented tooling.
Practical choice for terminal-centric testers who accept AI-assisted workflows
For security professionals comfortable in a terminal environment and prepared to validate agent output, gori is a practical option that connects live network traffic to AI-driven analysis. Its requirement for an MCP-capable client and its terminal-first design make it most suitable for engineers who prioritise automation-ready proxies and scripted test pipelines rather than GUI-based interception workflows.





