stealth-browser-launch

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 'cloakbrowser' Python package and references the 'cloakhq/cloakbrowser' Docker image to facilitate its core browser-cloaking functionality.
  • [COMMAND_EXECUTION]: The instructions involve several shell commands for environment preparation, including package installation ('apt', 'pip'), browser dependency setup ('playwright install-deps'), virtual display management ('Xvfb'), and container execution ('docker').
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of external web content (e.g., page titles and site data). While this presents a surface for indirect prompt injection, the examples provided do not demonstrate unsafe interpolation or a lack of sanitization that would lead to agent compromise.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — stealth-browser-launch