Back to skill

Security audit

Camofox Cloaked Browser

Security checks across malware telemetry and agentic risk

Overview

This skill transparently teaches an agent to use a local anti-detection browser, with sensitive capabilities disclosed and scoped to user-directed browser work.

Install this only if you intentionally need cloaked/anti-detection browsing. Keep the server bound to localhost unless you set strong bearer tokens, avoid storing CAMOFOX_URL globally in Hermes, review cookie/profile/trace storage, and disable crash telemetry with CAMOFOX_CRASH_REPORT_ENABLED=false if privacy is important.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Content
## Operating model

Camofox Browser is a Node server and OpenClaw plugin wrapper around Camoufox, a Firefox-based anti-detection browser.

Primary local startup:
Confidence
80% confidence
Finding
model; Always follow these rule

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.