⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
merklemap-osint
>
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
Not yet listed on ClawHub or SkillsMP
// README
MerkleMap OSINT Skill for OpenClaw
Turn any OpenClaw agent into a professional OSINT analyst. Subdomain discovery, certificate auditing, typosquatting detection, real-time CT monitoring, risk scoring, and beautiful HTML reports — all through natural language.
What Can It Do?
| Capability | Description |
|---|---|
| Subdomain Enumeration | Discover all known subdomains via Certificate Transparency logs |
| Typosquatting Detection | Find lookalike/phishing domains using Levenshtein fuzzy matching |
| Certificate Audit | List all certs for a host, flag expired, weak, or expiring ones |
| Certificate Deep Dive | Full X.509 details, issuer chain, CT log presence for any cert |
| Live CT Monitoring | Real-time SSE stream of newly discovered hostnames |
| Risk Scoring | Automatic 0–100 risk score based on scan findings |
| Subdomain Categorization | Auto-classify hosts (mail, api, admin, dev, cdn, auth...) |
| CA Trust Analysis | Detect unusual CAs, self-signed certs, CA sprawl |
| Temporal Anomaly Detection | Spot suspicious bursts of new subdomains |
| Wildcard Cert Mapping | Map which subdomains are covered by wildcard certs |
| Change Detection | Diff current scan vs previous report — catch what changed |
| Multi-Domain Scanning | Batch scan multiple domains with comparison table |
| Executive Summaries | Non-technical summaries for management and stakeholders |
| HTML Report Export | Professional dark-themed dashboard, print-ready |
| JSON Export | Machine-readable output for SIEMs and automation pipelines |
Quick Start
1. Install
git clone https://github.com/laikhtman/merklemap-openclaw-skill.git ~/.openclaw/skills/merklemap-osint
2. Configure
Get your API key at merklemap.com/user-profile/api, then:
export MERKLEMAP_API_KEY='your_api_token_here'
3. Use
Restart OpenClaw and start talking:
> Do a full recon on tesla.com and generate a report
That's it. The skill handles everything — subdomain discovery, certificate checks, risk analysis, categorization, and outputs a professional HTML report.
Usage Examples
Surface Mapping
Find all subdomains of example.org
Do a full recon on tesla.com
Scan tesla.com, spacex.com, and boring.co
Certificate Auditing
What certificates are active for mail.proton.me?
Are there any expired certs on api.example.com?
Show me the full details of cert with SHA-256 ab12cd34...
Typosquatting & Phishing Detection
Check for typosquatting domains targeting mybrand.com
Find lookalike domains for openai.com
Real-Time Monitoring
Monitor new certificates being issued for example.com
Show me the live CT log stream
Reports & Exports
Full recon on example.com — generate report
Audit certs for mail.example.com and export as HTML and JSON
Generate a report for the typosquatting scan on mybrand.com
Change Detection
What changed on example.com since the last scan?
Compare current state of tesla.com with previous report
Smart Workflows
The skill doesn't just call APIs — it thinks. When you say "full recon", it automatically:
- Enumerates all subdomains (with auto-pagination)
- Categorizes every hostname (mail, api, admin, dev...)
- Pulls certificates for key infrastructure
- Analyzes CA diversity and trust
- Maps wildcard certificate coverage
- Detects temporal anomalies in discovery dates
- Calculates a risk score (0–100)
- Writes an executive summary
- Flags all security issues by severity
- Generates a beautiful HTML dashboard
HTML Reports
Professional, self-contained HTML reports with zero external dependencies.
What's included:
- Risk score banner (color-coded 0–100)
- Executive summary for non-technical stakeholders
- Summary metric cards
- Key findings ranked by severity (HIGH / MEDIUM / INFO)
- Subdomain table with category badges
- Discovery timeline
- Certificate Authority analysis
- Wildcard certificate coverage map
- Full certificate table with status badges
- Change detection diff (when comparing scans)
- Typosquatting results with risk ratings
Features:
- Dark theme by default, light theme on request
- Print-ready (
@media printstyles) for PDF export - Mobile responsive
- Sticky table headers
Reports are saved as merklemap-report-{domain}-{date}.html.
Risk Scoring
Every scan produces a 0–100 risk score based on real findings:
| Score | Rating | Meaning |
|---|---|---|
| 0–20 | Low | Well-managed infrastructure |
| 21–40 | Moderate | Some attention needed |
| 41–60 | Elevated | Significant issues found |
| 61–80 | High | Immediate attention recommended |
| 81–100 | Critical | Serious security concerns |
Factors include: expired certs, weak keys, self-signed certs, exposed dev/staging hosts, unusual CAs, subdomain bursts, typosquatting domains, and more.
Compatibility
| Platform | Status |
|---|---|
| OpenClaw | Fully supported |
| OpenCode | Fully supported |
| Anthropic Agent SDK 1.0 | Compatible |
| Claude Code | Compatible via skill loading |
API Reference
This skill uses the MerkleMap API:
| Endpoint | Description |
|---|---|
GET /v1/search | Subdomain search (wildcard + Levenshtein) |
GET /v1/certificates/{hostname} | List certificates for a hostname |
GET /v1/certificates/hash/{sha256} | Get full certificate details |
GET /v1/live-tail | Real-time CT log stream (SSE) |
A paid MerkleMap subscription is required. Get your API key here.
Contributing
Contributions are welcome! Feel free to:
- Open an issue for bugs or feature requests
- Submit a PR with improvements
- Share your use cases
License
MIT - see LICENSE for details.
Built by @laikhtman | Powered by MerkleMap
// HOW IT'S BUILT
KEY FILES