camofox-cloaked-browser
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads the
@askjo/camofox-browserpackage from the NPM registry and fetches browser binaries during the installation process. - [COMMAND_EXECUTION]: Utilizes shell utilities including
npx,npm,git, andcurlto start the browser server, install dependencies, and interact with the REST API endpoints. - [DATA_EXFILTRATION]: While the skill manages sensitive browser data such as cookies and session profiles, it provides explicit warnings against exposing the no-auth local server to external networks and includes instructions on how to disable upstream crash-reporting telemetry via environment variables.
- [PROMPT_INJECTION]: As a tool designed for web browsing and content extraction, the skill inherently processes untrusted data from external websites. It addresses this by providing clear rules for when the tool should be used and warning against global environment configurations that might lead to accidental automated routing of browser traffic.
Audit Metadata