Agent skill

Multi Account Isolation

by antibrow in antibrow/anti-detect-browser-skills

Verify that browser profiles are actually isolated from one another instead of assuming it - confirm each profile's timezone agrees with its own exit IP, that WebRTC exposes only the proxy, that…

MITAuto-check passedGame Development

Install Multi Account Isolation

skills CLI
$ npx skills add antibrow/anti-detect-browser-skills --skill multi-account-isolation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install antibrow/anti-detect-browser-skills multi-account-isolation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/antibrow/anti-detect-browser-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/multi-account-isolation .claude/skills/multi-account-isolation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
multi-account-isolation
GitHub stars
17
Used in
1 other repo
Token cost
~2.9k tokens
SKILL.md length
1,290 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Verify that browser profiles are actually isolated from one another instead of assuming it - confirm each profile's timezone agrees with its own exit IP, that WebRTC exposes only the proxy, that…

  • Works in 5 steps: Profile name reused? list_profiles, or… → Same address twice? Confirm each… → Clock disagrees with the address? Print… → …
  • Several of your own accounts
  • SKILL.md covers The configuration invariant, Setup under test, The checks and Reading a failure, plus 4 more sections
  • Calls python, npx and npm; reaches antibrow.com; needs ANTI_DETECT_BROWSER_KEY

What it does

Multi Account Isolation is an agent skill from antibrow/anti-detect-browser-skills. Verify that browser profiles are actually isolated from one another instead of assuming it - confirm each profile's timezone agrees with its own exit IP, that WebRTC exposes only the proxy, that canvas and WebGL hashes stay identical across relaunches of one profile, and that no two profiles share a persona, a cookie jar, or an address. Use when several of your own accounts or test identities run from one machine and the setup needs checking, when a profile tested clean but something still looks off, when…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Game Development, covering 3D graphics and WebGL. It works with Model Context Protocol. The repository describes itself as: Launch and manage anti-detect browsers with unique real-device fingerprints for multi-account operations, web scraping, ad verification, and AI agent automation. The licence is MIT.

When your agent uses it

  • Several of your own accounts
  • Test identities run from one machine and the setup needs checking
  • A profile tested clean but something still looks off
  • Choosing which detection suites to run (CreepJS

Example prompts

  • “profile isolation check”
  • “fingerprint consistency test”
  • “timezone mismatch”
  • “/multi-account-isolation”

Requirements

  • Python 3
  • Node.js
  • A credential in ANTI_DETECT_BROWSER_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Profile name reused? list_profiles, or compare browser.profile_dir per identity. Two identities in one directory explains everything else…
  2. Same address twice? Confirm each public_ip is distinct.
  3. Clock disagrees with the address? Print browser.timezone and browser.public_ip together.
  4. Persona regenerated? If the canvas hash moved between launches, the profile is not frozen - check whether profile_dir or the cache…
  5. Only then the fingerprint itself, verified with the suites above rather than assumed.

What it can do on your machine

Read from SKILL.md and the folder at commit b800e3a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • npx
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • antibrow.com

    Also links to:

    • browserleaks.com
    • abrahamjuliot.github.io
    • whoer.net
    • pixelscan.net
    • liarjs.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTI_DETECT_BROWSER_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Multi Account Isolation loads about 2.9k tokens when it runs. Until then it costs about 256 tokens; SKILL.md has 1,290 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~256
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from antibrow/anti-detect-browser-skills at commit b800e3a, republished under its MIT licence (© antibrow). 1,290 words, ~2,856 tokens.

Download SKILL.mdSave it as .claude/skills/multi-account-isolation/SKILL.md (or your agent's skills folder).
name
multi-account-isolation
description
Verify that browser profiles are actually isolated from one another instead of assuming it - confirm each profile's timezone agrees with its own exit IP, that WebRTC exposes only the proxy, that canvas and WebGL hashes stay identical across relaunches of one profile, and that no two profiles share a persona, a cookie jar, or an address. Use when several of your own accounts or test identities run from one machine and the setup needs checking, when a profile tested clean but something still looks off, when choosing which detection suites to run (CreepJS, whoer, browserleaks WebRTC, pixelscan, liarjs), when auditing what a vendor runtime does with API and proxy credentials, or when asking which layers browser isolation cannot cover at all. Also for 'profile isolation check', 'fingerprint consistency test', 'timezone mismatch', 'WebRTC leak', 'canvas hash unstable', 'account association', 'temporary profile', '防关联', '多账号', '隔离自检'. The SDK is anti-detect-browser; MCP is browser-mcp-agent.
license
MIT

Profile Isolation - verifying it, not assuming it

A profile that looks isolated usually is not. The failures are boring and mechanical: a timezone that does not match the exit IP, a WebRTC candidate carrying the real address, a canvas hash that changes on every read, two profiles that ended up on the same persona. This skill is the check list for catching those before they matter.

Authorized use only. This is for identities you own or are authorized to operate: your own accounts, your own test fixtures, your own QA fleet, and your own anti-fraud stack. It is not for accessing systems without authorization, for accounts that are not yours, or for creating fake accounts or engagement. Comply with the terms of the sites you automate and with applicable law - see Acceptable use.

What this does not claim. Passing every check below means the browser layer is internally consistent. It does not mean a given site will treat two profiles as unrelated: things entirely outside the browser - a shared payment instrument, a shared contact detail, identical activity patterns - are not something any browser setting reaches. Treat a clean result as "the technical layer is not the problem", not as a guarantee.

For the SDK that creates and launches these profiles, see the anti-detect-browser skill.

The configuration invariant

One identity gets one of everything. Any cell shared between two identities is a defect to find:

identity  →  profile  →  persona  →  proxy  →  timezone
   1      :     1     :     1     :    1    :     1

Profiles are unlimited and free on every antibrow plan, so there is never a reason to reuse one. "Log out and log back in as the other identity" inside one profile defeats the entire setup - the cookie jar and localStorage are the point.

Setup under test

typescript
import { AntiDetectBrowser } from 'anti-detect-browser'

const ab = new AntiDetectBrowser({ key: process.env.ANTI_DETECT_BROWSER_KEY })

const identities = [
  { profile: 'fixture-us-01', proxy: process.env.PROXY_US_1, tags: ['Windows 10', 'Chrome'] },
  { profile: 'fixture-us-02', proxy: process.env.PROXY_US_2, tags: ['Apple Mac', 'Safari'] },
  { profile: 'fixture-de-01', proxy: process.env.PROXY_DE_1, tags: ['Windows 10', 'Edge'] },
]

for (const id of identities) {
  const { browser, page } = await ab.launch({
    profile: id.profile,              // isolated cookies, storage, login state
    proxy: id.proxy,                  // from the environment, one per identity
    fingerprint: { tags: id.tags },   // drawn once, frozen, replayed after
    label: id.profile,                // address-bar tag drawn by the kernel, unreadable from the page
  })
  // ... run the checks below, then ...
  await browser.close()
}

Python, same on-disk profile format:

python
import os
from antibrow import launch

with launch(
    profile="fixture-us-01",
    proxy=os.environ["PROXY_US_1"],   # from the environment, never a literal
    geoip=True,            # timezone + WebRTC follow the proxy exit
    label="fixture-us-01",
) as browser:
    page = browser.new_page()
    print(browser.timezone, browser.public_ip)

The checks

Run each profile through its own proxy, and assert rather than eyeball.

#CheckHowFails when
1Timezone matches the exit IPbrowser.timezone vs the country of browser.public_ipgeoip was disabled, or timezone was forced to something the IP contradicts. This is the single most common defect.
2WebRTC exposes only the proxybrowserleaks.com/webrtcICE candidates still carry a local or real public address
3Canvas hash is stable across launchesRead it, close, relaunch the same profile, read againThe two reads differ - a value that changes every read is itself an anomaly, and it means the persona is not frozen
4Worker and main thread agreeCreepJSUA, languages, hardwareConcurrency, timezone or GPU differ when re-read inside a Web Worker
5One GPU across three interfacesCreepJS, or read WebGL / WebGL2 / WebGPU directlyadapter.info.vendor does not match the unmasked WebGL renderer family
6No two profiles share a personaDiff browser.persona across the fleetTwo profiles report the same UA, screen geometry and seeds
7No two profiles share an addressCollect browser.public_ip for the fleetTwo identities came out of the same exit, or the same /24
8Cookie jars are separateCompare browser.profile_dir across the fleet, then inspect user-data/ inside eachTwo identities resolve to one directory, or one directory holds state belonging to another identity
9One identity, one profile treeConfirm every launch of a name passes the same temporary valueA managed gmail and a temporary gmail are two different profiles with two personas and two cookie jars. A script that disagrees with itself about temporary is running two identities under one name and will look like a logged-out session, not like a bug
10Whole-stack coherencewhoer.net, pixelscan.netIP, timezone and locale disagree at a glance
11Consistency rules in CInpx liarjs (liarjs.dev)Any of ~40 open-source cross-layer rules fail - this is the one that runs unattended

Checks 1, 3 and 7 are the ones worth wiring into CI: they are cheap, deterministic, and they catch the defects that actually recur.

Reading a failure

Work down in this order, cheapest first - a fingerprint is almost never the actual cause:

  1. Profile name reused? list_profiles, or compare browser.profile_dir per identity. Two identities in one directory explains everything else. Directories are named after the profile's id, not its name, so match on profile.json inside rather than on the folder name.
  2. Same address twice? Confirm each public_ip is distinct.
  3. Clock disagrees with the address? Print browser.timezone and browser.public_ip together.
  4. Persona regenerated? If the canvas hash moved between launches, the profile is not frozen - check whether profile_dir or the cache directory changed under it.
  5. Only then the fingerprint itself, verified with the suites above rather than assumed.
Show full SKILL.md (547 more words)Show less

What the runtime touches, and how to check it

Any tool that drives logged-in sessions receives cookies and proxy credentials, so it is fair to ask what it does with them. For antibrow:

ArtifactWhere it livesWho sees it
Cookies, localStorage, login state~/.anti-detect-browser/profiles/<id>/user-data/ on your disk, or profiles-temp/<id>/ for a temporary profileLocal. Cloud sync is opt-in per profile: a launch never creates a cloud profile by itself, and sync: true is what puts one there. Check which profiles sync before assuming they stay on the machine
Persona (persona.json)same profile directory, written once and frozenLocal
Profile identity record (profile.json)same profile directory; the id it holds is what names the directoryLocal. It is why a rename does not cost a persona, and why the folder name is not the profile name
Proxy URL and its credentialspassed to the kernel at launch; answered in the network stack (HTTP 407 / SOCKS5 RFC 1929) so no extension holds themThe kernel process and your proxy provider
API keyyour environment, or ~/.antibrow/license.keyExchanged with antibrow.com for a short-lived license token, roughly once a day

The kernel is a closed-source Chromium build - that is the tradeoff for the spoofing living in C++ rather than in an injectable script - so verify behaviour rather than take it on faith:

bash
python -m antibrow info          # kernels, profiles, license state, cache dir
python
browser.plan.redacted_args()     # exact kernel command line, secrets masked - safe to paste in a bug report

Point it at a proxy whose logs you can read, or at a local MITM proxy, and watch what leaves the machine during a launch. Pin the SDK version and check the published hash (npm view anti-detect-browser@2.8.0 dist.integrity) so the code you audited is the code that runs. If a deployment must not phone home at all, this is the wrong tool: license verification is compiled into the kernel and there is no offline mode.

What isolation cannot cover

Worth stating plainly, because a clean check list invites the wrong conclusion:

  • Anything outside the browser. A shared payment instrument, a shared contact detail, a shared payout destination - no browser setting touches these, and they are the strongest correlators that exist.
  • Activity patterns. Identical timing, identical content, identical interaction targets. Not a technical property.
  • Identity verification. A document check is not a fingerprint problem.
  • A platform's own decision. Nothing here changes how a site chooses to treat an account.

If every check passes and something still looks wrong, the cause is in this list, not in the browser layer.

Acceptable use

Intended: verifying isolation between identities you own; running client accounts with the account holder's authorization; building QA fixtures that emulate distinct devices; testing your own anti-fraud and correlation logic; auditing what a browser runtime does with your credentials.

Out of scope, and not supported: accessing any system without authorization; logging into accounts that are not yours; credential stuffing or account takeover; creating fake accounts, reviews or engagement; circumventing an authentication, payment or authorization control; scraping personal data in violation of applicable law; working around a platform's enforcement decision.

Complying with the terms of the platforms being used, and with applicable law, is the operator's responsibility. Report abuse or a security issue via the contact at https://antibrow.com.

  • anti-detect-browser - the SDK, profiles, personas, proxies and REST API that create the setup being verified here
  • browser-mcp-agent - MCP server mode, for letting an AI agent drive a single profile itself

© antibrow, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in multi-account-isolation of antibrow/anti-detect-browser-skills.

Open the folder on GitHubat commit b800e3a

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in antibrow/anti-detect-browser-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Multi Account Isolation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Multi Account Isolation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Multi Account Isolation this skillantibrow/anti-detect-browser-skills171 repos~2.9kAutomated safety check: PassMIT
Blockbench Pluginsjasonjgardner/blockbench-mcp-plugin495—~2.8kAutomated safety check: PassGPL-3.0
Octocode Mannequinbgauryy/octocode949—~1.2kAutomated safety check: PassMIT
Unreal Scene Buildingflopperam/unreal-engine-mcp1.1k—~1.4kAutomated safety check: PassNone
Investigate Canvas UIatty303/pob-web103—~1.4kAutomated safety check: PassMIT
Fal Assetsrehan-remade/universal-modder5.8k—~2kAutomated safety check: NotesMIT

Similar skills

  • Blockbench Plugins

    jasonjgardner/blockbench-mcp-plugin

    Blockbench plugin/extension development for the 3D modeling tool.

    495 GitHub stars~2.8k tokensUpdated 7 days ago
    Game DevelopmentAuto-check passed
  • Octocode Mannequin

    bgauryy/octocode

    Poses and animates a 22-bone anatomical humanoid rig with joint range-of-motion limits, using a Node CLI, a Three.js viewer and WebMCP tools an agent can drive live.

    949 GitHub stars~1.2k tokensUpdated today
    Game DevelopmentAuto-check passed
  • Unreal Scene Building

    flopperam/unreal-engine-mcp

    Guides scene and world building in Unreal Engine through the Flopperam MCP: placing actors, sculpting landscapes, scattering foliage, editing materials and verifying the level.

    1.1k GitHub stars~1.4k tokensUpdated 3 mo ago
    Game DevelopmentAuto-check passed
  • Investigate Canvas UI

    atty303/pob-web

    Investigate this repository's Canvas/WebGL UI with Playwright MCP Vision Mode.

    103 GitHub stars~1.4k tokensUpdated 4 days ago
    Game DevelopmentAuto-check passed
  • Fal Assets

    rehan-remade/universal-modder

    Generate game assets with fal (fal.ai) through the fal MCP server, the um fal CLI (REST) or fal api.

    5.8k GitHub stars~2k tokensUpdated today
    Game DevelopmentAuto-check: notes
  • Threejs Game Director

    mintdotgg/mint-threejs-skills

    Build or upgrade complete Three.js browser games by coordinating gameplay, Mint MCP assets, graphics, UI, debugging, performance, QA, and release.

    114 GitHub stars~1.4k tokensUpdated 2 mo ago
    Game DevelopmentAuto-check passed

More from antibrow/anti-detect-browser-skills

  • Browser MCP Agent

    antibrow/anti-detect-browser-skills

    Give an AI agent its own real browser over MCP tool calls - launch, navigate, click, fill, screenshot, extract text, run JS - with a kernel-level real-device fingerprint and a persistent profile, so…

    17 GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check: warnings
  • Anti Detect Browser

    antibrow/anti-detect-browser-skills

    Drive Chromium from standard Playwright APIs with a real-device fingerprint applied in the kernel, one persistent isolated profile per identity, and a per-profile proxy whose exit IP sets timezone…

    17 GitHub stars~9.8k tokensUpdated 1 mo ago
    Auto-check: warnings
  • Multi Account Scraping

    antibrow/anti-detect-browser-skills

    Run the same scrape or task across many accounts at once - each in its own browser profile with its own fingerprint, cookies and exit IP - and read data from sites that need a session or that answer…

    17 GitHub stars~3.7k tokensUpdated 1 mo ago
    Auto-check: warnings

Questions about Multi Account Isolation

What does Multi Account Isolation do?

Verify that browser profiles are actually isolated from one another instead of assuming it - confirm each profile's timezone agrees with its own exit IP, that WebRTC exposes only the proxy, that…. Multi Account Isolation is an agent skill from antibrow/anti-detect-browser-skills. Verify that browser profiles are actually isolated from one another instead of assuming it - confirm each profile's timezone agrees with its own exit IP, that WebRTC exposes only the proxy, that canvas and WebGL hashes stay identical across relaunches of one profile, and that no two profiles share a persona, a cookie jar, or an address.

When should I use Multi Account Isolation?

Multi Account Isolation fits situations like: several of your own accounts; test identities run from one machine and the setup needs checking; A profile tested clean but something still looks off; choosing which detection suites to run (CreepJS.

How do I install Multi Account Isolation in Claude Code?

Run `npx skills add antibrow/anti-detect-browser-skills --skill multi-account-isolation -a claude-code`. Or copy the skill folder (multi-account-isolation in antibrow/anti-detect-browser-skills) into .claude/skills/multi-account-isolation in your project. Claude Code loads it when a task matches its description.

How do I install Multi Account Isolation in Codex?

Run `npx skills add antibrow/anti-detect-browser-skills --skill multi-account-isolation -a codex`. Or copy the skill folder (multi-account-isolation in antibrow/anti-detect-browser-skills) into .agents/skills/multi-account-isolation in your project. Codex loads it when a task matches its description.

Can I use Multi Account Isolation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add antibrow/anti-detect-browser-skills --skill multi-account-isolation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/multi-account-isolation, .gemini/skills/multi-account-isolation, .github/skills/multi-account-isolation and .opencode/skills/multi-account-isolation in your project.

What does Multi Account Isolation need to run?

Going by SKILL.md and its folder, Multi Account Isolation needs the command-line tools its instructions call (python, npx and npm) and credentials named ANTI_DETECT_BROWSER_KEY. Our summary lists: Python 3; Node.js; A credential in ANTI_DETECT_BROWSER_KEY.

Does Multi Account Isolation access the network?

SKILL.md names 6 domains. In commands or code: antibrow.com; the agent is likely to contact it when it follows the instructions. As links in the text: browserleaks.com, abrahamjuliot.github.io, whoer.net, pixelscan.net and liarjs.dev. This is read from the text; nothing was executed.

Is Multi Account Isolation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Multi Account Isolation use?

Multi Account Isolation is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Multi Account Isolation use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Multi Account Isolation?

Skills that share tags, products or a category with Multi Account Isolation: Blockbench Plugins (jasonjgardner/blockbench-mcp-plugin, 495 stars), Octocode Mannequin (bgauryy/octocode, 949 stars), Unreal Scene Building (flopperam/unreal-engine-mcp, 1.1k stars) and Investigate Canvas UI (atty303/pob-web, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Multi Account Isolation?

antibrow (a GitHub user) maintains it in antibrow/anti-detect-browser-skills, which has 17 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on August 28, 2026.

Source: antibrow/anti-detect-browser-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.