camoufox

Warn

Audited by Socket on Mar 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The fragment describes a coherent, dual-use automation framework for anti-detection browser automation. While there is no direct evidence of credential harvesting or remote exfiltration in the fragment, the reliance on external setup scripts, VNC-based CAPTCHA flows, and persistent profile storage introduces supply-chain and privacy risks. The overall risk is moderate: review integrity of scripts, ensure signed sources, enforce least-privilege deployment, and confirm data handling policies for persistent browser profiles. Not inherently malicious based on the fragment alone, but warrants careful governance and secure supply-chain practices.

Confidence: 59%Severity: 62%
Audit Metadata
Analyzed At
Mar 5, 2026, 06:23 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fcamoufox%2F@3b7cfa2e3a876a24cbb18e6e3306fe4b48969453