Back to skill

Security audit

Cloakbrowser Stealth

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed stealth-fetch tool, but it is built to bypass anti-bot protections on third-party sites and gives too little guidance around authorization, privacy, and retained browser identity data.

Install only if you have authorization to automate the target sites and are comfortable using a stealth browser that may bypass service controls. Avoid using it with accounts, session cookies, personal data, or untrusted proxies, and treat screenshots and extracted HTML/text as potentially sensitive data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly promotes stealth browser automation to bypass bot detection on protected sites and includes screenshot capture and content extraction, but provides no warning or guardrails around privacy, terms of service, consent, or lawful data handling. In this context, the omission is security-relevant because it normalizes covert access to protected content and increases the likelihood of misuse for unauthorized scraping or collection of sensitive page data.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The documentation encourages use of persistent browser profiles and proxy-based geolocation matching without warning that profiles can retain cookies, localStorage, and other identifying/session data, and that proxies may route sensitive traffic through third parties. In a stealth-automation skill, this increases the chance of covert tracking, account/session leakage, and misuse of retained identity data across runs.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This section prominently markets anti-detection, fingerprint spoofing, and CAPTCHA/anti-bot evasion capabilities without any caution about legal, policy, account, or abuse risks. Because the skill’s stated purpose is to bypass bot protections on protected sites, the omission materially increases the likelihood of misuse for unauthorized scraping, controls evasion, and deception of target services.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.