REPOGEO REPORT · LITE
ghostsecurity/reaper
Default branch main · commit 5f00c2a4 · scanned 6/8/2026, 12:12:00 PM
GitHub: 867 stars · 91 forks
Action plan is what to do next — copy-pasteable changes prioritized by impact. Category visibility is the real GEO test: when a user asks an AI a brand-free question that should surface ghostsecurity/reaper, does the AI actually recommend you — or your competitors? Objective checks verify the metadata signals AI engines weight first. Self-mention check detects whether AI even knows you exist by name.
Action plan — copy-paste fixes
3 prioritized changes generated by gemini-2.5-flash. Mark items done after you ship the fix.
- highreadme#1Reposition README opening to clarify core function and audience
Why:
CURRENTMITM HTTPS proxy for application security testing. Intercepts in-scope traffic, logs requests and responses to a local database, and provides a CLI for searching and inspecting captured traffic. Reaper is designed to be easy to use by humans and AI agents alike. For AI agent integration, see Ghost Security Skills.
COPY-PASTE FIXReaper is a MITM HTTPS proxy specifically designed for **web application vulnerability testing and analysis**. It intercepts in-scope traffic, logs requests and responses to a local database, and provides a CLI for searching and inspecting captured traffic. While designed for ease of use by humans, Reaper also supports integration with AI agents for automated security workflows; see Ghost Security Skills for details.
- mediumtopics#2Refine topics to reinforce core identity as a vulnerability testing proxy
Why:
CURRENTagentic, ai, appsec, automation, proxy, security
COPY-PASTE FIXappsec, proxy, vulnerability-testing, web-security, traffic-analysis, mitm-proxy, automation, ai, agentic, security
- lowcomparison#3Add a comparison section to differentiate from common alternatives
Why:
COPY-PASTE FIXAdd a new section to the README, e.g., '## Why Reaper? How does it compare to Burp Suite or OWASP ZAP?' Briefly explain Reaper's unique focus on AI agent integration and streamlined CLI for specific vulnerability testing workflows, contrasting it with the broader feature sets of other proxies.
Category GEO backends resolved for this scan: google/gemini-2.5-flash, deepseek/deepseek-v4-flash
Category visibility — the real GEO test
Brand-free queries asked to google/gemini-2.5-flash. Did AI recommend you, or someone else?
Same questions for every model — switch tabs to compare answers and rankings.
- PortSwigger Burp Suite Professional · recommended 2×
- zaproxy/zaproxy · recommended 2×
- Fiddler Everywhere · recommended 2×
- mitmproxy/mitmproxy · recommended 1×
- Charles Proxy · recommended 1×
- CATEGORY QUERYHow can I intercept and analyze web traffic for application security vulnerabilities?you: not recommendedAI recommended (in order):
- PortSwigger Burp Suite Professional
- OWASP ZAP (Zed Attack Proxy) (zaproxy/zaproxy)
- Fiddler Everywhere
- mitmproxy (mitmproxy/mitmproxy)
- Charles Proxy
- Wireshark
AI recommended 6 alternatives but never named ghostsecurity/reaper. This is the gap to close.
Show full AI answer
- CATEGORY QUERYWhat tools help automate web application vulnerability testing using a proxy?you: not recommendedAI recommended (in order):
- PortSwigger Burp Suite Professional
- OWASP ZAP (zaproxy/zaproxy)
- Acunetix
- Invicti
- AppScan Standard
- Fiddler Everywhere
AI recommended 6 alternatives but never named ghostsecurity/reaper. This is the gap to close.
Show full AI answer
Objective checks
Rule-based audits of metadata signals AI engines weight most.
- Metadata completenesspass
- README presencepass
Self-mention check
Does AI even know your repo exists when asked about it directly?
- Compared to common alternatives in this category, what is the core differentiator of ghostsecurity/reaper?passAI named ghostsecurity/reaper explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- If a team adopts ghostsecurity/reaper in production, what risks or prerequisites should they evaluate first?passAI named ghostsecurity/reaper explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- In one sentence, what problem does the repo ghostsecurity/reaper solve, and who is the primary audience?passAI named ghostsecurity/reaper explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
Embed your GEO score
Drop this badge into the README of ghostsecurity/reaper. It auto-updates whenever the report is rescanned and links back to the latest report — easy public proof that you care about AI discoverability.
[](https://repogeo.com/en/r/ghostsecurity/reaper)<a href="https://repogeo.com/en/r/ghostsecurity/reaper"><img src="https://repogeo.com/badge/ghostsecurity/reaper.svg" alt="RepoGEO" /></a>Subscribe to Pro for deep diagnoses
ghostsecurity/reaper — Lite scans stay free; this card itemizes Pro deep limits vs Lite.
- Deep reports10 / month
- Brand-free category queries5 vs 2 in Lite
- Prioritized action items8 vs 3 in Lite