Back to skill

Security audit

Dolphin Anty

Security checks across malware telemetry and agentic risk

Overview

This skill openly provides anti-detect browser automation with profile deletion, account workflows, profile warmup, persisted sessions, and arbitrary page JavaScript, but it lacks enough scoping and safeguards for those high-impact capabilities.

Install only if you understand and are authorized to use Dolphin Anty for the target sites and accounts. Use a dedicated limited token, protect or relocate the plaintext .token file, avoid running custom JavaScript from untrusted prompts, do not use it for unauthorized account creation or stealth scraping, and review profile deletion or cloud-synced session changes before running commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The `custom` task accepts attacker-controlled JavaScript from `--code` and executes it with `page.evaluate(...)` in the context of whatever page/profile is opened. That enables arbitrary actions in authenticated browser sessions such as reading page data, interacting with sites, or triggering sensitive state-changing requests, which is dangerous for an agent skill unless tightly constrained.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description includes broad trigger phrases such as account registration, account checking, scraping, and general browser automation, which can cause the agent to invoke the skill in situations where the user did not explicitly consent to stealth browser use. Because this skill controls anti-detect browser profiles and local automation, accidental invocation materially increases the chance of privacy-invasive or policy-violating actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises deleting profiles, launching stealth browsers, scraping data, warming profiles, and executing custom JavaScript without prominent safety warnings, consent checks, or usage restrictions. These actions can destroy data, access sensitive account state, or facilitate deceptive automation, especially because they operate through real persisted browser identities whose cookies and storage sync back to the cloud.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
Executing arbitrary browser JavaScript without an explicit safety barrier is a real risk in an automation skill because untrusted task input can manipulate live sessions and access sensitive page data. In this context, the capability is broader than the other task-specific functions and effectively turns the tool into a general-purpose browser payload runner.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The script stores the API token in a predictable plaintext file (`../.token`) immediately after accepting it, without warning the user about credential persistence, file location, or filesystem exposure. Because this token grants access to the Dolphin Anty account/API, any other local user, malware, backup system, or accidental repository inclusion could disclose the credential and enable unauthorized API access.

Ssd 4

Medium
Confidence
97% confidence
Finding
This skill is explicitly centered on anti-detection browser identities, stealth automation, account registration/checking, and profile warming to build organic-looking history, which are common evasion patterns used to bypass fraud, abuse-detection, and platform enforcement controls. The context makes the finding more dangerous, not less, because the skill normalizes and operationalizes deceptive account and scraping workflows rather than presenting a legitimate constrained administrative use case.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal