Agent skill

Tls Fingerprint Impersonation

by uphiago in uphiago/recon-skills

Spoof TLS ClientHello and JA4 fingerprints for browser impersonation.

MITAuto-check passedSecurity

Install Tls Fingerprint Impersonation

skills CLI
$ npx skills add uphiago/recon-skills --skill tls-fingerprint-impersonation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills tls-fingerprint-impersonation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/tls-fingerprint-impersonation .claude/skills/tls-fingerprint-impersonation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tls-fingerprint-impersonation
GitHub stars
1.3k
Token cost
~2.1k tokens
SKILL.md length
577 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Spoof TLS ClientHello and JA4 fingerprints for browser impersonation.

  • Works in 7 steps: Browser Profile Selection → Basic Request → With Proxy → …
  • Tasks that involve Cryptography
  • SKILL.md covers When to Use, Prerequisites, Quick Detection and Procedure, plus 4 more sections
  • Calls python3, curl and pip; reaches howsmyssl.com and cloudflare.com

What it does

Tls Fingerprint Impersonation is an agent skill from uphiago/recon-skills. Spoof TLS ClientHello and JA4 fingerprints for browser impersonation.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, httpx, python3

It sits in Security, covering Cryptography. It works with Rust and iOS. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Tasks that involve Cryptography

Example prompts

  • “/tls-fingerprint-impersonation”

Requirements

  • Python 3
  • Node.js
  • Compatibility (from SKILL.md): Requires curl, httpx, python3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Browser Profile Selection
  2. Basic Request
  3. With Proxy
  4. Custom Headers
  5. Cookie Session
  6. Fingerprint Selection Logic
  7. JA4 Hash Validation

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • curl
    • pip
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • howsmyssl.com
    • cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, httpx, python3

    From compatibility in the SKILL.md frontmatter.

Context cost

Tls Fingerprint Impersonation loads about 2.1k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 577 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 577 words, ~2,099 tokens.

Download SKILL.mdSave it as .claude/skills/tls-fingerprint-impersonation/SKILL.md (or your agent's skills folder).
name
tls-fingerprint-impersonation
description
Spoof TLS ClientHello and JA4 fingerprints for browser impersonation.
compatibility
Requires curl, httpx, python3
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, TLS, JA3, JA4, fingerprint, impersonation, HTTP, browser
category
recon
related_skills
http2-header-impersonation, stealth-browser-launch, humanize-automation

TLS Fingerprint Impersonation

Spoof TLS ClientHello parameters — cipher suites, key exchange groups, signature algorithms, and extension order — to match real browsers at the JA3/JA4 fingerprint level. Uses patched rustls to rebuild the TLS layer with browser-identical configurations. Bypasses TLS fingerprinting detection (Cloudflare, Akamai, F5) that flags non-browser TLS stacks. Supports 20 browser profiles including Chrome 100-142, Firefox 128-144, Safari iOS 18, and OkHttp 3-5 (Android).

When to Use

  • Target returns 403/blocked on curl/httpx even with correct User-Agent headers.
  • Cloudflare or Akamai is fingerprinting TLS ClientHello (JA3/JA4 mismatch with browser).
  • API probing requires mobile-app impersonation (OkHttp fingerprint for Android).
  • Need high-throughput HTTP requests that pass TLS fingerprint checks without running a full browser.
  • Target shows different behavior based on TLS fingerprint (mobile vs desktop endpoints).

Prerequisites

  • terminal with python3.
  • Python: pip install impit (wraps the Rust library via PyO3).
  • Or Node.js: npm install impit (native binding).
  • Or Rust: impit crate with patched dependencies in Cargo.toml.

Quick Detection

bash
# Check if a target blocks non-browser TLS
curl --max-time 30 --connect-timeout 10 -sk https://target.com | head -1
# If 403, test with browser impersonation:
python3 -c "
from impit import Impit
impit = Impit.builder().with_fingerprint('chrome142').build()
r = impit.get('https://target.com').text
print(r[:200])
"

Procedure

Phase 1 — Browser Profile Selection

Choose the right fingerprint for your target:

ProfileUse caseKey differentiator
chrome142Modern desktopLatest Chrome, post-quantum KEX (X25519MLKEM768), GREASE
chrome100Legacy systemsOlder cipher suites, no GREASE in key exchange
firefox144Firefox desktopDifferent pseudo-header order, FFDHE groups, SHA-1 signatures
safari_ios18iOS mobile3DES ciphers, duplicate signature algorithm, no session tickets
okhttp4Android appsBoringSSL profile, no GREASE, no ECH, simpler cipher suites
chrome124Common defaultGood balance of modern compatibility and detection pass rate
python
from impit import Impit

# Chrome 142 (latest)
client = Impit.builder().with_fingerprint("chrome142").build()

# Firefox 144
client = Impit.builder().with_fingerprint("firefox144").build()

# Safari iOS 18 (mobile API endpoints)
client = Impit.builder().with_fingerprint("ios18").build()

# OkHttp 4 (Android app impersonation)
client = Impit.builder().with_fingerprint("okhttp4").build()
Phase 2 — Basic Request
python
from impit import Impit

impit = (
    Impit.builder()
    .with_fingerprint("chrome142")
    .with_ignore_tls_errors(True)  # for self-signed certs during recon
    .with_http3()                   # HTTP/3 support
    .with_fallback_to_vanilla(True) # retry without fingerprint if blocked
    .build()
)

response = impit.get("https://target.com")
print(response.status_code)
print(response.headers)
print(response.text()[:500])
Phase 3 — With Proxy
python
impit = (
    Impit.builder()
    .with_fingerprint("chrome142")
    .with_proxy("http://user:pass@residential-proxy:8080")
    .with_default_timeout(15_000)  # 15 seconds in milliseconds
    .build()
)

response = impit.get("https://target.com/api/endpoint")
Phase 4 — Custom Headers
python
# Custom headers are merged with fingerprint defaults
# Fingerprint headers have lower priority — custom headers win on conflict
response = impit.get(
    "https://target.com/api/v1",
    headers={
        "X-Forwarded-For": "[REDACTED_IP]",
        "Authorization": "Bearer token",
    }
)
python
from impit.cookie import Jar

impit = (
    Impit.builder()
    .with_fingerprint("chrome142")
    .with_cookie_store(Jar())  # persistent cookie jar
    .build()
)

# Login
impit.post("https://target.com/login", json={
    "username": "admin", "password": "admin"
})

# Authenticated request — cookies preserved automatically
response = impit.get("https://target.com/dashboard")
Phase 6 — Fingerprint Selection Logic

Choose based on target characteristics:

python
def select_fingerprint(target_url):
    """Auto-select browser fingerprint based on target."""
    if "mobile" in target_url or "api/v2" in target_url:
        return "ios18"
    elif "android" in target_url or "play.google" in target_url:
        return "okhttp4"
    elif target_url.startswith("https://"):
        return "chrome142"  # default for modern HTTPS
    return "chrome124"
Phase 7 — JA4 Hash Validation

Verify your TLS fingerprint is working correctly:

bash
# Test against a site that returns JA4 hash in response headers
python3 -c "
from impit import Impit
impit = Impit.builder().with_fingerprint('chrome142').build()
r = impit.get('https://cloudflare.com/cdn-cgi/trace')
print(r.text())
# Look for JA4 hash in trace output or response headers
"

Browser Fingerprint Reference

TLS Configuration per Browser
FeatureChrome 142Firefox 144Safari iOS 18OkHttp 4
TLS versions1.3 + 1.21.3 + 1.21.3 + 1.21.3 + 1.2
GREASE cipher✅ (pos 1)❌✅❌
GREASE key exchange✅ (pos 1)❌✅❌
Post-quantum (MLKEM768)✅✅✅❌
FFDHE groups❌✅ (2048/3072)❌❌
SHA-1 signatures❌✅✅ (legacy)✅ (RSA only)
ECH GREASE✅✅❌❌
3DES ciphers❌❌✅❌
Certificate compressionBrotliZlib+Brotli+ZstdZlib❌
Delegated credentials❌✅❌❌
Session tickets✅✅❌✅
Duplicate signatures❌❌✅ (RsaPssRsaSha384)❌
Show full SKILL.md (238 more words)Show less
HTTP/2 Settings per Browser
BrowserStream WindowConnection WindowPseudo-Header Order
Chrome6,291,45615,663,105:method :authority :scheme :path
Firefox131,07212,517,377:method :path :authority :scheme
Safari iOS2,097,15210,485,760:method :scheme :authority :path
OkHttp16,777,21616,777,216:method :path :authority :scheme
Multipart Boundary Format
BrowserFormatExample
Chrome----WebKitFormBoundary + 16 alphanumeric----WebKitFormBoundaryx8fH3kLm9pQr2sTv
Firefox----geckoformboundary + hex u64 values----geckoformboundary3fa8c10e5d6b2904
OkHttpUUID v4550e8400-e29b-41d4-a716-446655440000

Pitfalls

  • Not all sites use TLS fingerprinting. Test with curl first — if it works, TLS fingerprinting is not the blocker.
  • Fingerprint must match User-Agent. Using Chrome TLS with Firefox UA headers will be detected.
  • HTTP/1.1-only sites don't use HTTP/2 impersonation. The with_http3() flag only matters for sites that support it.
  • OkHttp 3 is TLS 1.2 only. Some modern servers reject TLS 1.2 connections.
  • TLS fingerprint caching means first request is slowest. CryptoProvider instances are cached per fingerprint — subsequent requests are fast.
  • Vanilla fallback may leak your real TLS fingerprint. Disable vanilla_fallback if stealth is critical.

Verification

  1. Confirm TLS fingerprint matches target browser using https://www.howsmyssl.com/ or Cloudflare trace endpoint.
  2. Check cf-ja4 response header when hitting Cloudflare-protected sites.
  3. Verify response status changes from 403 → 200 when using browser fingerprint vs vanilla curl.
  4. Test with multiple browser profiles to find the one that passes the target's detection.
  • http2-header-impersonation — HTTP/2 pseudo-header ordering and SETTINGS frame matching.
  • stealth-browser-launch — Full browser automation with C++ fingerprint patches for JS-heavy targets.
  • humanize-automation — Human-like interaction patterns for behavioral detection bypass.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/tls-fingerprint-impersonation of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Tls Fingerprint Impersonation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tls Fingerprint Impersonation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tls Fingerprint Impersonation this skilluphiago/recon-skills1.3k—~2.1kAutomated safety check: PassMIT
Constant-Time Analysistrailofbits/skills7.5k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Azure Keyvault Keys Rustaiskillstore/marketplace4334 repos~1.1kAutomated safety check: PassNone
Pump Securitynirholas/pump-fun-sdk134—~892Automated safety check: PassCustom licence
Azure Keyvault Keys Rustmicrosoft/skills3.1k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.5k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Azure Keyvault Keys Rust

    aiskillstore/marketplace

    Azure Key Vault Keys SDK for Rust. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 4 repos~1.1k tokens
    SecurityAuto-check passed
  • Pump Security

    nirholas/pump-fun-sdk

    Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency…

    134 GitHub stars~892 tokensUpdated yesterday
    SecurityAuto-check passed
  • Azure Keyvault Keys Rust

    microsoft/skills

    Official

    Azure Key Vault Keys library for Rust. An agent skill from microsoft/skills.

    3.1k GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Common Security Audit

    HoangNguyen0403/agent-skills-standard

    Probe for hardcoded secrets, injection surfaces, unguarded routes, business logic flaws, and platform-specific weaknesses across backend (Node, Go, Java, Python, Rust), frontend (React, Angular…

    572 GitHub stars~977 tokensUpdated yesterday
    SecurityAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Tls Fingerprint Impersonation

What does Tls Fingerprint Impersonation do?

Spoof TLS ClientHello and JA4 fingerprints for browser impersonation. Tls Fingerprint Impersonation is an agent skill from uphiago/recon-skills. Spoof TLS ClientHello and JA4 fingerprints for browser impersonation.

When should I use Tls Fingerprint Impersonation?

Tls Fingerprint Impersonation fits situations like: tasks that involve Cryptography.

How do I install Tls Fingerprint Impersonation in Claude Code?

Run `npx skills add uphiago/recon-skills --skill tls-fingerprint-impersonation -a claude-code`. Or copy the skill folder (recon/tls-fingerprint-impersonation in uphiago/recon-skills) into .claude/skills/tls-fingerprint-impersonation in your project. Claude Code loads it when a task matches its description.

How do I install Tls Fingerprint Impersonation in Codex?

Run `npx skills add uphiago/recon-skills --skill tls-fingerprint-impersonation -a codex`. Or copy the skill folder (recon/tls-fingerprint-impersonation in uphiago/recon-skills) into .agents/skills/tls-fingerprint-impersonation in your project. Codex loads it when a task matches its description.

Can I use Tls Fingerprint Impersonation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill tls-fingerprint-impersonation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tls-fingerprint-impersonation, .gemini/skills/tls-fingerprint-impersonation, .github/skills/tls-fingerprint-impersonation and .opencode/skills/tls-fingerprint-impersonation in your project.

What does Tls Fingerprint Impersonation need to run?

Going by SKILL.md and its folder, Tls Fingerprint Impersonation needs the command-line tools its instructions call (python3, curl, pip and npm). Our summary lists: Python 3; Node.js. Compatibility (from SKILL.md): Requires curl, httpx, python3.

Does Tls Fingerprint Impersonation access the network?

SKILL.md names 2 domains. In commands or code: howsmyssl.com and cloudflare.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Tls Fingerprint Impersonation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tls Fingerprint Impersonation use?

Tls Fingerprint Impersonation is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tls Fingerprint Impersonation use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tls Fingerprint Impersonation?

Skills that share tags, products or a category with Tls Fingerprint Impersonation: Constant-Time Analysis (trailofbits/skills, 7.5k stars), Security Review (github/awesome-copilot, 40k stars), Azure Keyvault Keys Rust (aiskillstore/marketplace, 433 stars) and Pump Security (nirholas/pump-fun-sdk, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tls Fingerprint Impersonation?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,293 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.