Back to skill

Security audit

Patchright Stealth Browsing

Security checks across malware telemetry and agentic risk

Overview

This skill is a browser automation guide whose stated purpose is to bypass anti-bot protections, so it needs review before use even though no malware was found in the packaged files.

Install only if you have a legitimate, authorized need to test or automate sites you control or are permitted to assess. Treat saved cookies, profiles, screenshots, and videos as sensitive credentials or personal data, and review the private patchright-mcp server separately before trusting it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly describes the skill as enabling stealth browser automation to bypass bot detection and remain undetected. In the context of an agent skill, this is dangerous because it operationalizes evasion of access controls and anti-abuse defenses, which can facilitate unauthorized scraping, account abuse, or circumvention of website protections.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly supports stealth automation, cookie extraction/restoration, screenshots, and structured page snapshots, but it does not warn that these actions can capture or persist sensitive browser data such as authentication tokens, personal content, and session state. In a stealth-browsing context, that omission is more dangerous because the skill is designed to operate on protected sites and preserve access, increasing the likelihood of privacy-invasive or unauthorized data handling.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill documents video recording of browser sessions to disk but does not warn that recordings may capture credentials, personal data, MFA prompts, internal pages, or other sensitive activity. Because this skill is intended for stealth interaction with anti-bot-protected sites, silent recording to local files creates meaningful privacy and data-exposure risk if users are unaware or if artifacts are retained insecurely.

Ssd 4

Medium
Confidence
95% confidence
Finding
The file frames a stealth-browsing workflow around evading site protections and avoiding detection, which goes beyond neutral automation documentation. Because this content is meant to be appended to an agent's instructions, it can directly guide an autonomous system to defeat defensive controls during real interactions with protected services.

Ssd 2

High
Confidence
98% confidence
Finding
The skill description explicitly states its purpose is to bypass bot detection systems such as Cloudflare, Akamai, and Datadome. That is a direct statement of intent to circumvent security controls, making the risk substantially higher than a generic browser automation tool because the surrounding skill context is offensive rather than administrative or educational.

Ssd 4

High
Confidence
97% confidence
Finding
The usage section provides a practical step-by-step workflow for using protected-target tooling, bypassing limitations, and handling anti-bot blockers, CAPTCHAs, and timeouts. This materially increases exploitability by turning an abstract evasion concept into actionable operator guidance for defeating defenses in live environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.