{"id":"cc5c527f-fe34-4f24-b357-0214e7e26f74","entityType":"agent","slug":"clawhub-skills-admin4giter-muki-fingerprint","name":"muki-fingerprint","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-admin4giter-muki-fingerprint","canonicalPath":"/agent/clawhub-skills-admin4giter-muki-fingerprint","generatedAt":"2026-10-09T21:05:32.470Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"MUKI asset fingerprinting tool for red team reconnaissance. Use when performing authorized penetration testing, asset discovery, service fingerprinting, vulnerability scanning, and attack surface mapping. Supports active/passive fingerprinting with 30,000+ signatures, sensitive path detection, and sensitive information extraction. Requires explicit authorization for target systems. --- name: muki-fingerprint description: MUKI asset fingerprinting tool for red team reconnaissance. Use when performing authorized penetration testing, asset discovery, service fingerprinting, vulnerability scanning, and attack surface mapping. Supports active/passive fingerprinting with 30,000+ signatures, sensitive path detection, and sensitive information extraction. Requires explicit authorization for target syst","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:admin4giter:muki-fingerprint","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/admin4giter/muki-fingerprint","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/admin4giter/muki-fingerprint","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"MUKI asset fingerprinting tool for red team reconnaissance. Use when performing authorized penetration testing, asset discovery, service fingerprinting, vulnera"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"single","status":"self-declared"},{"label":"multiple","status":"self-declared"},{"label":"with","status":"self-declared"},{"label":"muki","status":"self-declared"},{"label":"in","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":6,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"single","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"multiple","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"with","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"muki","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"in","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:single|supported|profile capability:multiple|supported|profile capability:with|supported|profile capability:muki|supported|profile capability:in|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T05:56:15.877Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T05:56:15.877Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T05:56:15.877Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:admin4giter:muki-fingerprint","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T21:05:32.470Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-admin4giter-muki-fingerprint/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\nname: muki-fingerprint\ndescription: MUKI asset fingerprinting tool for red team reconnaissance. Use when performing authorized penetration testing, asset discovery, service fingerprinting, vulnerability scanning, and attack surface mapping. Supports active/passive fingerprinting with 30,000+ signatures, sensitive path detection, and sensitive information extraction. Requires explicit authorization for target systems.\nmetadata:\n  openclaw:\n    emoji: fingerprint\n    category: security-assessment\n    version: 1.0.0\n    author: OpenClaw\n    requirements:\n      - Linux amd64 environment\n      - Network access to target\n      - Explicit authorization for targets\n    allowed-tools: [\"Bash\"]\n---\n\n# MUKI Asset Fingerprinting Tool\n\nMUKI is an active asset fingerprinting tool built for red team operations. It enables security researchers to rapidly pinpoint vulnerable systems from chaotic C-class segments and massive asset lists.\n\n## Prerequisites\n\n- Linux amd64 system\n- Network access to target systems\n- **Explicit written authorization** for all target systems\n\n## Quick Start\n\n```bash\n# Scan single URL\nmuki -u https://target.com\n\n# Scan multiple URLs from file\nmuki -l targets.txt\n\n# Scan with proxy\nmuki -u https://target.com -p socks5://127.0.0.1:1080\n\n# Disable specific modules\nmuki -u https://target.com -A -N  # No active, no directory scan\n```\n\n## Command Options\n\n```\n-h, --help            Show help\n-u, --url string      Single URL to scan\n-l, --list string     File containing URLs (one per line)\n-o, --output string   Output file path\n-p, --proxy string    Proxy server (http:// or socks5://)\n-t, --thread int      Number of threads (default: 20, max: 100)\n-A, --no-active       Disable active fingerprint scanning\n-N, --no-dir          Disable directory scanning  \n-x, --no-passive      Disable passive fingerprint scanning\n```\n\n## Core Modules\n\n### 1. Active Fingerprinting (-A to disable)\nSends protocol-specific probes to identify services with high confidence.\n- 300+ active fingerprint rules\n- Covers SSH, RDP, web servers, databases\n- Protocol-specific probes\n\n### 2. Passive Fingerprinting (-x to disable)\nAnalyzes response artifacts without additional traffic.\n- 30,000+ precision fingerprints\n- HTTP headers analysis\n- TLS JA3 signatures\n- HTML/CMS patterns\n- WAF detection\n\n### 3. Sensitive Path Detection (-N to disable)\nChecks for high-risk paths using curated dictionaries.\n- Admin interfaces (/admin, /manage)\n- Config files (.env, config.php)\n- Version control (/.git, /.svn)\n- Vulnerability endpoints (Actuator, ThinkPHP routes)\n- Backup files (.sql, .tar.gz)\n\n### 4. Sensitive Information Extraction\nAutomatically extracts high-risk information from responses.\n\n**Categories:**\n- **Credentials**: Passwords, API keys, JDBC strings\n- **Personal Data**: Phone numbers, emails, ID cards\n- **Financial**: Bank cards\n- **System Info**: Internal IPs, versions\n- **Vulnerability Indicators**: ID parameters, redirect URLs\n\n## Output Formats\n\n### JSON Output\n```json\n{\n  \"target\": \"https://example.com\",\n  \"fingerprints\": [\n    {\n      \"service\": \"Apache\",\n      \"version\": \"2.4.41\",\n      \"confidence\": \"high\"\n    }\n  ],\n  \"sensitive_paths\": [\n    {\n      \"path\": \"/admin\",\n      \"status\": 200,\n      \"risk\": \"high\"\n    }\n  ],\n  \"sensitive_data\": [\n    {\n      \"type\": \"email\",\n      \"value\": \"admin@example.com\",\n      \"source\": \"response body\"\n    }\n  ]\n}\n```\n\n### Excel Output\nStructured .xlsx report with multiple sheets:\n- Asset inventory\n- Service fingerprints\n- Sensitive paths\n- Extracted data\n\n## Workflow\n\n### Standard Reconnaissance\n```bash\n# 1. Prepare target list\ncat > targets.txt << 'EOF'\nhttps://target1.com\nhttps://target2.com\n192.168.1.0/24\nEOF\n\n# 2. Run full scan\nmuki -l targets.txt -o results.json\n\n# 3. Review results\ncat results.json | jq '.fingerprints[]'\n\n# 4. Generate Excel report\nmuki -l targets.txt -o report.xlsx\n```\n\n### Stealth Scan (with proxy)\n```bash\n# Use Tor proxy for anonymity\nmuki -u https://target.com -p socks5://127.0.0.1:9050\n\n# Or use HTTP proxy\nmuki -u https://target.com -p http://127.0.0.1:8080\n```\n\n### Targeted Scan\n```bash\n# Fast scan - only passive fingerprinting\nmuki -u https://target.com -A -N\n\n# Deep scan - all modules\nmuki -u https://target.com -t 50\n```\n\n## Fingerprint Databases\n\n### finger.json (30,000+ fingerprints)\nPassive fingerprint database covering:\n- Web frameworks (React, Vue, Django, Spring)\n- Middleware (Apache, Nginx, IIS, Tomcat)\n- CMS (WordPress, Drupal, Joomla)\n- WAFs (Cloudflare, ModSecurity, AWS WAF)\n- APIs (GraphQL, REST, SOAP)\n- Known vulnerabilities (CVE signatures)\n\n### active_finger.json (300+ rules)\nActive probing rules for:\n- Web servers\n- Databases (MySQL, PostgreSQL, MongoDB)\n- Remote access (SSH, RDP, Telnet)\n- Services (Redis, Elasticsearch, Docker)\n\n### Rules.yml\nSensitive information extraction rules organized by groups:\n- **疑似漏洞**: ID parameters (SQLi indicators)\n- **指纹信息**: URL redirects, sensitive paths\n- **敏感信息**: Passwords, accounts, JDBC strings\n- **基础信息**: Emails, ID cards, phones, bank cards\n\n## Best Practices\n\n### 1. Authorization\n- Always obtain written authorization before scanning\n- Define scope clearly (IPs, domains, time windows)\n- Respect rate limits and business hours\n\n### 2. Stealth\n- Use proxies for external targets\n- Adjust thread count to avoid detection\n- Consider using -A -N for passive-only recon\n\n### 3. Data Handling\n- Store results securely\n- Encrypt sensitive findings\n- Limit access to authorized personnel only\n- Delete data after engagement ends\n\n### 4. False Positive Reduction\n- Cross-reference findings with manual verification\n- Use multiple detection methods\n- Check context of extracted sensitive data\n\n## Legal and Ethical Considerations\n\n**WARNING**: This tool is for authorized security testing only.\n\n- Unauthorized scanning may violate laws (CFAA, Computer Misuse Act, etc.)\n- Only use on systems you own or have explicit permission to test\n- Extracting sensitive data without authorization is illegal\n- Report findings responsibly through proper channels\n\n## Integration\n\n### With Other Tools\n```bash\n# Chain with nuclei for vulnerability scanning\ncat muki_output.txt | nuclei -t cves/\n\n# Import to Burp Suite\ncat results.json | jq -r '.sensitive_paths[].path' > burp_scope.txt\n\n# Feed to SQLMap for SQL injection testing\ncat results.json | jq -r '.vulnerable_params[]' | sqlmap -m -\n```\n\n## Troubleshooting\n\n### High Memory Usage\n- Reduce thread count: `-t 10`\n- Scan in smaller batches\n- Disable passive fingerprinting: `-x`\n\n### False Positives\n- Verify findings manually\n- Check rule specificity in Rules.yml\n- Adjust confidence thresholds\n\n### Connection Issues\n- Check proxy configuration\n- Verify network connectivity\n- Increase timeout values\n\n## References\n\n- Original Repository: https://github.com/yingfff123/MUKI\n- Fingerprint Databases: See references/finger.json, active_finger.json\n- Extraction Rules: See references/Rules.yml\n\n## License\n\nMIT License - See original repository for details.\n","readmeExcerpt":"--- name: muki-fingerprint description: MUKI asset fingerprinting tool for red team reconnaissance. Use when performing authorized penetration testing, asset discovery, service fingerprinting, vulnerability scanning, and attack surface mapping. Supports active/passive fingerprinting with 30,000+ signatures, sensitive path detection, and sensitive information extraction. Requires explicit authorization for target syst","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# Scan single URL\nmuki -u https://target.com\n\n# Scan multiple URLs from file\nmuki -l targets.txt\n\n# Scan with proxy\nmuki -u https://target.com -p socks5://127.0.0.1:1080\n\n# Disable specific modules\nmuki -u https://target.com -A -N  # No active, no directory scan"},{"language":"text","snippet":"-h, --help            Show help\n-u, --url string      Single URL to scan\n-l, --list string     File containing URLs (one per line)\n-o, --output string   Output file path\n-p, --proxy string    Proxy server (http:// or socks5://)\n-t, --thread int      Number of threads (default: 20, max: 100)\n-A, --no-active       Disable active fingerprint scanning\n-N, --no-dir          Disable directory scanning  \n-x, --no-passive      Disable passive fingerprint scanning"},{"language":"json","snippet":"{\n  \"target\": \"https://example.com\",\n  \"fingerprints\": [\n    {\n      \"service\": \"Apache\",\n      \"version\": \"2.4.41\",\n      \"confidence\": \"high\"\n    }\n  ],\n  \"sensitive_paths\": [\n    {\n      \"path\": \"/admin\",\n      \"status\": 200,\n      \"risk\": \"high\"\n    }\n  ],\n  \"sensitive_data\": [\n    {\n      \"type\": \"email\",\n      \"value\": \"admin@example.com\",\n      \"source\": \"response body\"\n    }\n  ]\n}"},{"language":"bash","snippet":"# 1. Prepare target list\ncat > targets.txt << 'EOF'\nhttps://target1.com\nhttps://target2.com\n192.168.1.0/24\nEOF\n\n# 2. Run full scan\nmuki -l targets.txt -o results.json\n\n# 3. Review results\ncat results.json | jq '.fingerprints[]'\n\n# 4. Generate Excel report\nmuki -l targets.txt -o report.xlsx"},{"language":"bash","snippet":"# Use Tor proxy for anonymity\nmuki -u https://target.com -p socks5://127.0.0.1:9050\n\n# Or use HTTP proxy\nmuki -u https://target.com -p http://127.0.0.1:8080"},{"language":"bash","snippet":"# Fast scan - only passive fingerprinting\nmuki -u https://target.com -A -N\n\n# Deep scan - all modules\nmuki -u https://target.com -t 50"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"MUKI asset fingerprinting tool for red team reconnaissance. Use when performing authorized penetration testing, asset discovery, service fingerprinting, vulnerability scanning, and attack surface mapping. Supports active/passive fingerprinting with 30,000+ signatures, sensitive path detection, and sensitive information extraction. Requires explicit authorization for target systems. --- name: muki-fingerprint description: MUKI asset fingerprinting tool for red team reconnaissance. Use when performing authorized penetration testing, asset discovery, service fingerprinting, vulnerability scanning, and attack surface mapping. Supports active/passive fingerprinting with 30,000+ signatures, sensitive path detection, and sensitive information extraction. Requires explicit authorization for target syst","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":397,"uniquenessScore":63,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:05:32.470Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}