Vision & Scope
Problem
Security researchers, penetration testers, and QA engineers need realistic HTTP traffic data for:
- Tool evaluation — testing how security scanners, WAFs, or API gateways handle diverse traffic
- Dataset generation — creating reproducible training/evaluation datasets for ML-based security tools
- Pipeline testing — exercising data pipelines (SIEM, log aggregators, threat detection) with varied HTTP data
- Demo environments — generating realistic traffic for product demos without real user data
Manually crafting hundreds of diverse HTTP requests is tedious, error-prone, and non-reproducible. Existing tools either focus on load testing (not diversity) or require complex scripting.
Solution
request-mock-skills provides a single, deterministic entry point for generating HTTP traffic data with:
- One command — generate everything from a single CLI invocation
- Deterministic output — same seed, same output, every time
- Rich diversity — 16 built-in transforms across 100+ HTTP dimensions
- Multiple formats — 13 export formats for any downstream tool
- Streaming delivery — handle large datasets without memory pressure
- Config-driven — YAML/JSON config files for repeatable batch generation
Status
| Feature | Status | Description |
|---|---|---|
| Core generation | Done | Generate / GenerateOne converting RequestSpec to *har.Har |
| RequestSpec model | Done | 100+ parameters across flat + 9 group structures |
| Templates | Done | 20 built-in scenario templates |
| Transforms | Done | 16 built-in transforms with pluggable signature |
| CLI | Done | 11 subcommands with JSON envelope output |
| Export formats | Done | 13 formats (curl, wget, python, postman, xml, yaml, har, json, jsonl, csv, markdown, html, text) |
| Batch generation | Done | Config-driven with deterministic seed |
| HAR post-processing | Done | split, export, dedup, add-headers, clone |
| Channel streaming | Done | GenerateStream / Engine.RunStream |
| URL decomposition | Done | composeURL for decomposed URL fields |
| Engine | Done | Engine unified entry point for Config |
| Request chain | Done | Chain for sequential multi-step requests |
| Documentation | In progress | VitePress documentation site |
Future Directions
- More templates — additional protocol support (HTTP/2, HTTP/3 specific scenarios)
- More transforms — domain-specific transforms for security testing patterns
- Webhook delivery — stream generated entries to a webhook endpoint
- Plugin transforms — loadable shared library transforms
- OpenAPI/Swagger import — generate specs from API specifications
- HAR replay — replay generated HAR against a real target
- Performance benchmarks — benchmarks for large-scale generation (100k+ entries)
- Docker image — pre-built Docker images for CI/CD pipelines
- GitHub Actions — reusable action for CI integration
Design Principles
- Determinism first — reproducibility is the primary design constraint
- Progressive disclosure — simple CLI for common cases, full SDK for advanced use
- Format agnostic — HAR is the intermediate format; export to anything
- Composable — transforms, templates, and configs compose naturally
- No external services — everything runs locally, no network required