Skip to content

Vision & Scope ​

Problem ​

Security researchers, penetration testers, and QA engineers need realistic HTTP traffic data for:

  • Tool evaluation — testing how security scanners, WAFs, or API gateways handle diverse traffic
  • Dataset generation — creating reproducible training/evaluation datasets for ML-based security tools
  • Pipeline testing — exercising data pipelines (SIEM, log aggregators, threat detection) with varied HTTP data
  • Demo environments — generating realistic traffic for product demos without real user data

Manually crafting hundreds of diverse HTTP requests is tedious, error-prone, and non-reproducible. Existing tools either focus on load testing (not diversity) or require complex scripting.

Solution ​

request-mock-skills provides a single, deterministic entry point for generating HTTP traffic data with:

  • One command — generate everything from a single CLI invocation
  • Deterministic output — same seed, same output, every time
  • Rich diversity — 16 built-in transforms across 100+ HTTP dimensions
  • Multiple formats — 13 export formats for any downstream tool
  • Streaming delivery — handle large datasets without memory pressure
  • Config-driven — YAML/JSON config files for repeatable batch generation

Status ​

FeatureStatusDescription
Core generationDoneGenerate / GenerateOne converting RequestSpec to *har.Har
RequestSpec modelDone100+ parameters across flat + 9 group structures
TemplatesDone20 built-in scenario templates
TransformsDone16 built-in transforms with pluggable signature
CLIDone11 subcommands with JSON envelope output
Export formatsDone13 formats (curl, wget, python, postman, xml, yaml, har, json, jsonl, csv, markdown, html, text)
Batch generationDoneConfig-driven with deterministic seed
HAR post-processingDonesplit, export, dedup, add-headers, clone
Channel streamingDoneGenerateStream / Engine.RunStream
URL decompositionDonecomposeURL for decomposed URL fields
EngineDoneEngine unified entry point for Config
Request chainDoneChain for sequential multi-step requests
DocumentationIn progressVitePress documentation site

Future Directions ​

  • More templates — additional protocol support (HTTP/2, HTTP/3 specific scenarios)
  • More transforms — domain-specific transforms for security testing patterns
  • Webhook delivery — stream generated entries to a webhook endpoint
  • Plugin transforms — loadable shared library transforms
  • OpenAPI/Swagger import — generate specs from API specifications
  • HAR replay — replay generated HAR against a real target
  • Performance benchmarks — benchmarks for large-scale generation (100k+ entries)
  • Docker image — pre-built Docker images for CI/CD pipelines
  • GitHub Actions — reusable action for CI integration

Design Principles ​

  1. Determinism first — reproducibility is the primary design constraint
  2. Progressive disclosure — simple CLI for common cases, full SDK for advanced use
  3. Format agnostic — HAR is the intermediate format; export to anything
  4. Composable — transforms, templates, and configs compose naturally
  5. No external services — everything runs locally, no network required

Released under the MIT License.