stealth-browser-launch
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 'cloakbrowser' Python package and references the 'cloakhq/cloakbrowser' Docker image to facilitate its core browser-cloaking functionality.
- [COMMAND_EXECUTION]: The instructions involve several shell commands for environment preparation, including package installation ('apt', 'pip'), browser dependency setup ('playwright install-deps'), virtual display management ('Xvfb'), and container execution ('docker').
- [PROMPT_INJECTION]: The skill facilitates the ingestion of external web content (e.g., page titles and site data). While this presents a surface for indirect prompt injection, the examples provided do not demonstrate unsafe interpolation or a lack of sanitization that would lead to agent compromise.
Audit Metadata