camofox-cloaked-browser

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Downloads the @askjo/camofox-browser package from the NPM registry and fetches browser binaries during the installation process.
  • [COMMAND_EXECUTION]: Utilizes shell utilities including npx, npm, git, and curl to start the browser server, install dependencies, and interact with the REST API endpoints.
  • [DATA_EXFILTRATION]: While the skill manages sensitive browser data such as cookies and session profiles, it provides explicit warnings against exposing the no-auth local server to external networks and includes instructions on how to disable upstream crash-reporting telemetry via environment variables.
  • [PROMPT_INJECTION]: As a tool designed for web browsing and content extraction, the skill inherently processes untrusted data from external websites. It addresses this by providing clear rules for when the tool should be used and warning against global environment configurations that might lead to accidental automated routing of browser traffic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 12:39 AM
Security Audit — agent-trust-hub — camofox-cloaked-browser