Back to skill

Security audit

Camofox Default Browser

Security checks across malware telemetry and agentic risk

Overview

This skill openly provides anti-detection browser automation with cookie import and a background server, but its broad default-use guidance and weak safety scoping need review before installation.

Install only if you intend to use an anti-detection browser server for authorized automation. Treat imported cookie files as live account credentials, avoid enabling cookie import unless necessary, use access keys for the local server, review telemetry and profile persistence settings, and do not use it to bypass protections on sites where you lack permission.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill advertises operational capabilities that depend on system binaries and installation steps, but it does not declare corresponding permissions or clearly constrain shell-level actions. That mismatch weakens policy enforcement and reviewability, making it easier for an agent or operator to introduce package installation or local command execution without explicit user understanding.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly supports importing Netscape-format cookies for authenticated browsing but provides no warning about the sensitivity of session cookies, account takeover risk, or privacy implications. In an agent context, this can normalize handling live user session material and lead to accidental exfiltration, misuse of credentials, or unauthorized actions under a user's account.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is purpose-built to bypass bot detection, CAPTCHAs, and blocking, and later instructs the agent to retry when blocked, without any warning about legal, policy, privacy, or account-risk implications. In context, this increases the likelihood of unauthorized scraping or access against sites that are actively signaling anti-automation controls.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README promotes importing Netscape cookie files for authenticated sessions and using them to scrape behind login walls, but it does not clearly warn that cookies are effectively bearer tokens that can grant account access if mishandled. In the context of an anti-detection browser explicitly designed to bypass bot protections, this omission increases the likelihood of unsafe or unauthorized use of session cookies and account compromise.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes a cookie-import feature for authenticated browsing but does not warn users that imported session cookies can grant full account access and may bypass normal login safeguards. In an agent setting, this creates a serious risk of unauthorized account actions, session hijacking, and accidental handling of highly sensitive credentials.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The skill explicitly markets itself as bypassing CAPTCHAs, Cloudflare, and bot detection, which are access-control and abuse-prevention mechanisms. Providing evasion-oriented automation without justification or opt-in materially increases the likelihood of policy violations, scraping abuse, fraud enablement, and unauthorized access attempts.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The guidance to always prefer the anti-detection browser for public websites normalizes routine evasion behavior rather than limiting it to exceptional, authorized cases. In context, this makes the skill more dangerous because it operationalizes stealth browsing as the default path for broad internet interaction.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.