Agent skill

Http2 Header Impersonation

by uphiago in uphiago/recon-skills

Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.

MITAuto-check passedSecurity

Install Http2 Header Impersonation

skills CLI
$ npx skills add uphiago/recon-skills --skill http2-header-impersonation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills http2-header-impersonation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/http2-header-impersonation .claude/skills/http2-header-impersonation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
http2-header-impersonation
GitHub stars
1.3k
Token cost
~2.4k tokens
SKILL.md length
538 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.

  • Works in 6 steps: Full Browser Profile via impit → Manual Header Configuration → HTTP/2 SETTINGS Frame Spoofing → …
  • Security work in your project
  • SKILL.md covers When to Use, Prerequisites, Quick Detection and Procedure, plus 3 more sections
  • Calls curl, python3 and pip; reaches httpbin.org and nghttp2.org

What it does

Http2 Header Impersonation is an agent skill from uphiago/recon-skills. Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, httpx, python3

It sits in Security. It works with Android and iOS. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/http2-header-impersonation”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires curl, httpx, python3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Full Browser Profile via impit
  2. Manual Header Configuration
  3. HTTP/2 SETTINGS Frame Spoofing
  4. Pseudo-Header Order
  5. Header Prioritization
  6. Accept-Encoding Strategy

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • httpbin.org
    • nghttp2.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, httpx, python3

    From compatibility in the SKILL.md frontmatter.

Context cost

Http2 Header Impersonation loads about 2.4k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 538 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 538 words, ~2,415 tokens.

Download SKILL.mdSave it as .claude/skills/http2-header-impersonation/SKILL.md (or your agent's skills folder).
name
http2-header-impersonation
description
Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.
compatibility
Requires curl, httpx, python3
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, HTTP2, headers, fingerprint, impersonation, browser, JA4
category
recon
related_skills
tls-fingerprint-impersonation, stealth-browser-launch

HTTP/2 Header Impersonation

Spoof HTTP/2 SETTINGS frames, pseudo-header ordering, and browser-specific HTTP headers to match real browsers at the protocol level. Targets the detection gap between TLS fingerprinting (ClientHello) and JavaScript fingerprinting — the HTTP/2 connection setup and header structure that anti-bot systems analyze. Matches Chrome, Firefox, Safari iOS, and OkHttp (Android) profiles with exact window sizes, header list limits, and header ordering.

When to Use

  • TLS fingerprint is correct but target still detects non-browser HTTP behavior.
  • Target uses HTTP/2-specific detection (SETTINGS frame analysis, pseudo-header order).
  • Need browser-accurate sec-ch-ua, Accept, Accept-Encoding, Priority, and sec-fetch-* headers.
  • Mobile API endpoints require Android OkHttp header profiles.
  • Combining with TLS impersonation for a complete network-level browser profile.

Prerequisites

  • terminal with python3.
  • pip install impit (includes HTTP/2 impersonation via patched h2 library).
  • Or standalone: use the header lists below to configure curl/httpx manually.

Quick Detection

bash
# Check if target sends different responses based on HTTP headers
# Compare browser-like headers vs curl defaults

python3 -c "
import requests

# curl default headers
r1 = requests.get('https://target.com')
print(f'Default: {r1.status_code}')

# Browser-like headers
r2 = requests.get('https://target.com', headers={
    'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[REDACTED_IP] Safari/537.36',
    'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8',
    'Accept-Language': 'en-US,en;q=0.9',
    'Accept-Encoding': 'gzip, deflate, br, zstd',
    'sec-ch-ua': '\"Chromium\";v=\"142\", \"Google Chrome\";v=\"142\"',
    'sec-ch-ua-platform': '\"Windows\"',
    'sec-ch-ua-mobile': '?0',
})
print(f'Browser: {r2.status_code}')
"

Procedure

Phase 1 — Full Browser Profile via impit

The impit library applies HTTP/2 SETTINGS, pseudo-header order, and HTTP headers from a single profile:

python
from impit import Impit

# Chrome 142 — complete HTTP/2 + TLS + headers profile
impit = (
    Impit.builder()
    .with_fingerprint("chrome142")
    .build()
)

response = impit.get("https://target.com")
# Headers sent: sec-ch-ua, User-Agent, Accept, Accept-Encoding, Accept-Language,
#              sec-ch-ua-platform, sec-ch-ua-mobile, Priority, sec-fetch-*
# HTTP/2 SETTINGS: stream_window=6291456, conn_window=15663105, max_header=262144
# Pseudo-header order: :method :authority :scheme :path :protocol :status
Phase 2 — Manual Header Configuration

For curl/httpx without impit, configure headers manually to match browser profiles:

Chrome 142 Desktop Headers
bash
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" \
  -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[REDACTED_IP] Safari/537.36" \
  -H "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" \
  -H "Accept-Language: en-US,en;q=0.9" \
  -H "Accept-Encoding: gzip, deflate, br, zstd" \
  -H "sec-ch-ua: \"Chromium\";v=\"142\", \"Google Chrome\";v=\"142\", \"Not?A_Brand\";v=\"99\"" \
  -H "sec-ch-ua-arch: \"x86\"" \
  -H "sec-ch-ua-bitness: \"64\"" \
  -H "sec-ch-ua-full-version-list: \"Chromium\";v=\"142.0.7444.176\", \"Google Chrome\";v=\"142.0.7444.176\", \"Not?A_Brand\";v=\"[REDACTED_IP]\"" \
  -H "sec-ch-ua-mobile: ?0" \
  -H "sec-ch-ua-model: \"\"" \
  -H "sec-ch-ua-platform: \"Windows\"" \
  -H "sec-ch-ua-platform-version: \"15.0.0\"" \
  -H "sec-ch-ua-wow64: ?0" \
  -H "sec-fetch-dest: document" \
  -H "sec-fetch-mode: navigate" \
  -H "sec-fetch-site: none" \
  -H "sec-fetch-user: ?1" \
  -H "Upgrade-Insecure-Requests: 1" \
  -H "Priority: u=0, i"
Firefox 144 Desktop Headers
bash
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" \
  -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" \
  -H "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8" \
  -H "Accept-Language: en-US,en;q=0.5" \
  -H "Accept-Encoding: gzip, deflate, br, zstd" \
  -H "sec-ch-ua: \"Firefox\";v=\"144\", \"Not?A_Brand\";v=\"99\"" \
  -H "sec-ch-ua-mobile: ?0" \
  -H "sec-ch-ua-platform: \"Windows\"" \
  -H "sec-fetch-dest: document" \
  -H "sec-fetch-mode: navigate" \
  -H "sec-fetch-site: none" \
  -H "sec-fetch-user: ?1" \
  -H "TE: trailers" \
  -H "Upgrade-Insecure-Requests: 1" \
  -H "Priority: u=0, i"
Safari iOS 18 Headers
bash
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" \
  -H "User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.7 Mobile/15E148 Safari/604.1" \
  -H "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8" \
  -H "Accept-Language: en-US,en;q=0.9" \
  -H "Accept-Encoding: gzip, deflate, br" \
  -H "sec-fetch-dest: document" \
  -H "sec-fetch-mode: navigate" \
  -H "sec-fetch-site: none"
OkHttp 4 (Android) Headers
bash
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" \
  -H "User-Agent: okhttp/4.12.0" \
  -H "Accept: application/json, text/plain, */*" \
  -H "Accept-Language: en-US,en;q=0.9" \
  -H "Accept-Encoding: gzip, deflate, br" \
  -H "Connection: Keep-Alive"
Phase 3 — HTTP/2 SETTINGS Frame Spoofing

HTTP/2 SETTINGS frames are sent during connection setup. curl doesn't expose them — use impit or a patched HTTP client:

python
from impit import Impit

# Chrome HTTP/2 SETTINGS:
#   SETTINGS_MAX_CONCURRENT_STREAMS: 1000
#   SETTINGS_INITIAL_WINDOW_SIZE: 6291456
#   SETTINGS_MAX_HEADER_LIST_SIZE: 262144
# Firefox HTTP/2 SETTINGS:
#   SETTINGS_MAX_CONCURRENT_STREAMS: 125
#   SETTINGS_INITIAL_WINDOW_SIZE: 131072

impit = Impit.builder().with_fingerprint("chrome142").build()
response = impit.get("https://target.com")
Phase 4 — Pseudo-Header Order

Browsers send HTTP/2 pseudo-headers in specific orders. This is enforced at the h2 library level:

BrowserPseudo-Header Order
Chrome:method, :authority, :scheme, :path, :protocol, :status
Firefox:method, :path, :authority, :scheme, :protocol, :status
Safari iOS:method, :scheme, :authority, :path, :protocol, :status
OkHttp:method, :path, :authority, :scheme, :protocol, :status

Detection: Some reverse proxies inspect pseudo-header order to distinguish browsers. Firefox places :path before :authority — a unique fingerprint. Safari places :scheme second — another differentiator.

Phase 5 — Header Prioritization

Custom headers take priority over fingerprint defaults to avoid conflicts:

python
impit = Impit.builder().with_fingerprint("chrome142").build()

# Custom headers WIN over fingerprint defaults for same header name
response = impit.get("https://target.com", headers={
    "Authorization": "Bearer custom-token",
    "X-Custom-Header": "value",
})
# Authorization is added; all fingerprint headers still applied for unset names
Show full SKILL.md (230 more words)Show less
Phase 6 — Accept-Encoding Strategy

Browser Accept-Encoding values differ significantly:

BrowserAccept-Encoding
Chrome 142gzip, deflate, br, zstd
Chrome 100-116gzip, deflate, br
Firefoxgzip, deflate, br, zstd
Safari iOSgzip, deflate, br
OkHttp 4gzip, deflate, br

Detection: Some CDNs return different content based on Accept-Encoding (brotli vs zstd capability profiling). Match encoding capabilities to your target browser.

Pitfalls

  • curl cannot spoof HTTP/2 SETTINGS frames. Only use curl-based headers for HTTP/1.1 targets or when TLS fingerprinting is the primary concern, not HTTP/2.
  • Header order matters in HTTP/2. Some detectors check the order of header fields, not just their presence.
  • sec-ch-ua must match User-Agent. Using Chrome headers with Firefox UA creates an inconsistency that detectors flag.
  • sec-ch-ua format is version-specific. Chrome 100+ uses different brand strings than Chrome 124+.
  • Mobile headers without TLS matching is detectable. Using Safari iOS headers over a desktop TLS fingerprint is flagged.
  • Custom headers are deduplicated case-insensitively. Adding User-Agent as custom overrides the fingerprint's User-Agent.

Verification

  1. Test against https://httpbin.org/headers — verify all sent headers match the intended browser profile.
  2. For HTTP/2 SETTINGS verification, use https://nghttp2.org/httpbin/headers or a local nghttp2 server.
  3. Compare response size/content between browser-impostor and real browser — identical responses indicate the headers are accepted.
  4. Check Cloudflare cf-ja4 header — it encodes HTTP/2 fingerprint along with TLS.
  • tls-fingerprint-impersonation — TLS ClientHello and JA3/JA4 fingerprint spoofing.
  • stealth-browser-launch — Full browser automation with C++ fingerprint patches.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/http2-header-impersonation of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Http2 Header Impersonation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Http2 Header Impersonation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Http2 Header Impersonation this skilluphiago/recon-skills1.3k—~2.4kAutomated safety check: PassMIT
Reverse Flowlingbol088-spec/reverse-flow-skill935—~2.4kAutomated safety check: PassMIT
Mobile Security Experts7safe/android-h1210—~631Automated safety check: PassNone
Frida Mobile Securityindex-login/MobileRE-Skill111—~3kAutomated safety check: PassMIT
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
R0crawl Skillsmanyuegong33/r0crawl_skills305—~1.2kAutomated safety check: PassNone

Similar skills

  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    935 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Mobile Security Expert

    s7safe/android-h1

    移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

    210 GitHub stars~631 tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    111 GitHub stars~3k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    305 GitHub stars~1.2k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Exploiting Insecure Data Storage In Mobile

    mukul975/Anthropic-Cybersecurity-Skills

    Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Http2 Header Impersonation

What does Http2 Header Impersonation do?

Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile. Http2 Header Impersonation is an agent skill from uphiago/recon-skills. Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.

When should I use Http2 Header Impersonation?

Http2 Header Impersonation fits situations like: security work in your project.

How do I install Http2 Header Impersonation in Claude Code?

Run `npx skills add uphiago/recon-skills --skill http2-header-impersonation -a claude-code`. Or copy the skill folder (recon/http2-header-impersonation in uphiago/recon-skills) into .claude/skills/http2-header-impersonation in your project. Claude Code loads it when a task matches its description.

How do I install Http2 Header Impersonation in Codex?

Run `npx skills add uphiago/recon-skills --skill http2-header-impersonation -a codex`. Or copy the skill folder (recon/http2-header-impersonation in uphiago/recon-skills) into .agents/skills/http2-header-impersonation in your project. Codex loads it when a task matches its description.

Can I use Http2 Header Impersonation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill http2-header-impersonation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/http2-header-impersonation, .gemini/skills/http2-header-impersonation, .github/skills/http2-header-impersonation and .opencode/skills/http2-header-impersonation in your project.

What does Http2 Header Impersonation need to run?

Going by SKILL.md and its folder, Http2 Header Impersonation needs the command-line tools its instructions call (curl, python3 and pip). Our summary lists: Python 3. Compatibility (from SKILL.md): Requires curl, httpx, python3.

Does Http2 Header Impersonation access the network?

SKILL.md names 2 domains. In commands or code: httpbin.org and nghttp2.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Http2 Header Impersonation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Http2 Header Impersonation use?

Http2 Header Impersonation is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Http2 Header Impersonation use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Http2 Header Impersonation?

Skills that share tags, products or a category with Http2 Header Impersonation: Reverse Flow (lingbol088-spec/reverse-flow-skill, 935 stars), Mobile Security Expert (s7safe/android-h1, 210 stars), Frida Mobile Security (index-login/MobileRE-Skill, 111 stars) and Mira Risk Collect (vw2x/Mira, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Http2 Header Impersonation?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.