Back to skill

Security audit

Camofox Browser Selkies Test

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow instruction-only skill for using a named local Selkies/Camofox test browser stack, with no code, persistence, credentials, or hidden behavior found.

Install this if you want Codex/OpenClaw to recognize and use the named local Selkies test browser stack. Review commands before allowing Docker image pulls, container changes, or interactions with localhost services on ports 9378 and 3003.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.