Agent skill

Humanize Automation

by uphiago in uphiago/recon-skills

Human-like mouse, keyboard and scroll behavior for behavioral bot bypass.

MITAuto-check passedWriting & Content

Install Humanize Automation

skills CLI
$ npx skills add uphiago/recon-skills --skill humanize-automation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills humanize-automation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/humanize-automation .claude/skills/humanize-automation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
humanize-automation
GitHub stars
1.3k
Token cost
~2.2k tokens
SKILL.md length
737 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Human-like mouse, keyboard and scroll behavior for behavioral bot bypass.

  • Works in 5 steps: Default Humanization → Careful Mode (Slower, More Deliberate) → Custom Behavior Profile → …
  • Tasks that involve Humanizing AI text
  • SKILL.md covers When to Use, Prerequisites, Quick Start and Procedure, plus 4 more sections
  • Calls pip; reaches deviceandbrowserinfo.com

What it does

Humanize Automation is an agent skill from uphiago/recon-skills. Human-like mouse, keyboard and scroll behavior for behavioral bot bypass.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires python3

It sits in Writing & Content, covering Humanizing AI text. It works with Playwright. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Tasks that involve Humanizing AI text

Example prompts

  • “/humanize-automation”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires python3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Default Humanization
  2. Careful Mode (Slower, More Deliberate)
  3. Custom Behavior Profile
  4. Per-Call Overrides
  5. Standalone Humanization (Without CloakBrowser)

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • deviceandbrowserinfo.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires python3

    From compatibility in the SKILL.md frontmatter.

Context cost

Humanize Automation loads about 2.2k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 737 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 737 words, ~2,246 tokens.

Download SKILL.mdSave it as .claude/skills/humanize-automation/SKILL.md (or your agent's skills folder).
name
humanize-automation
description
Human-like mouse, keyboard and scroll behavior for behavioral bot bypass.
compatibility
Requires python3
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, humanize, behavioral, anti-bot, mouse, keyboard, automation
category
recon
related_skills
stealth-browser-launch, tls-fingerprint-impersonation

Humanize Automation

Replace instant programmatic interactions with human-like mouse movements, keyboard typing, and scroll patterns. Patches Playwright's API at the class level — page.click(), page.type(), page.fill(), and Locator methods are automatically replaced with Bézier-curved mouse paths, per-character typing with mistypes, and multi-phase scroll acceleration. One flag (humanize=True) enables all behavioral patches. No code changes required.

When to Use

  • Target uses behavioral bot detection (mouse trajectory analysis, typing speed profiling).
  • reCAPTCHA v3 scores are low (<0.3) despite correct browser fingerprint.
  • Target times out or challenges after rapid form submissions.
  • Need to simulate a real user browsing session for login or account creation.
  • Target uses requestAnimationFrame-based mouse movement tracking.

Prerequisites

  • terminal with python3.
  • cloakbrowser installed: pip install cloakbrowser.
  • Or standalone Playwright with custom patching: import patch_page from the humanize module.

Quick Start

python
from cloakbrowser import launch

browser = launch(humanize=True)
page = browser.new_page()
page.goto("https://target.com/login")

# All interactions are automatically humanized
page.locator("#email").fill("user@example.com")     # per-character timing
page.locator("#password").fill("password123")       # with thinking pauses
page.locator("button[type=submit]").click()         # Bézier curve movement
browser.close()

Procedure

Phase 1 — Default Humanization

One flag enables all behavior patches:

python
browser = launch(
    headless=False,
    proxy="http://residential-proxy:port",
    geoip=True,
    humanize=True,  # enables all behavioral patches
)
page = browser.new_page()
page.goto("https://target.com")

# All Playwright interactions are replaced with human-like equivalents
page.locator("input[name='search']").fill("restricted query")
page.locator("button[type='submit']").click()
Phase 2 — Careful Mode (Slower, More Deliberate)

For sites that profile interaction speed:

python
browser = launch(
    humanize=True,
    human_preset="careful",  # slower typing, more idle pauses
)

Careful preset changes: typing 100±50ms (vs 70±40ms), click aim 80-180ms (vs 60-140ms), idle_between_actions enabled with 0.4-1.0s pauses.

Phase 3 — Custom Behavior Profile

Override individual parameters for site-specific tuning:

python
from cloakbrowser import HumanConfig

custom = HumanConfig(
    typing_delay=150,
    typing_delay_spread=60,
    typing_pause_chance=0.15,
    mistype_chance=0.03,
    mouse_wobble_max=2.0,
    click_aim_delay_input=(100, 200),
    scroll_delta_base=(60, 100),
    idle_between_actions=True,
    idle_between_duration=(0.5, 1.5),
)

browser = launch(humanize=True, human_config=custom)
Phase 4 — Per-Call Overrides

Override behavior for individual interactions:

python
# Slow, careful typing for password field
page.locator("#password").fill("secret", human_config={"typing_delay": 200})

# Fast click (bypass aim delay)
page.locator("#submit").click(human_config={"click_aim_delay_input": (0, 0)})
Phase 5 — Standalone Humanization (Without CloakBrowser)

Patch an existing Playwright page:

python
from playwright.sync_api import sync_playwright
from cloakbrowser.human import patch_page, resolve_config

pw = sync_playwright().start()
browser = pw.chromium.launch()
page = browser.new_page()

# Apply humanization to an existing page
config = resolve_config("default")
patch_page(page, config)

# All interactions now humanized
page.locator("#email").fill("user@example.com")

Behavioral Parameters Reference

Mouse Movement
ParameterDefaultEffect
mouse_steps_divisor8Controls smoothness (lower = smoother, more steps)
mouse_min_steps25Minimum steps per movement
mouse_max_steps80Maximum steps per movement
mouse_wobble_max1.5 pxSideways sinusoidal wobble amplitude
mouse_overshoot_chance0.15Probability of overshooting target
mouse_overshoot_px(3, 6) pxOvershoot distance

Movement algorithm: Cubic Bézier curve with 2 random perpendicular control points → ease-in-out cubic easing → sinusoidal wobble → 15% overshoot chance with correction.

Keyboard Typing
ParameterDefaultEffect
typing_delay70 msAverage per-character delay
typing_delay_spread40 msRandom spread around delay
typing_pause_chance0.10Thinking pause probability per character
typing_pause_range(400, 1000) msThinking pause duration
mistype_chance0.02Typo probability per character
mistype_delay_notice(100, 300) msTime before noticing typo
mistype_delay_correct(50, 150) msTime to correct typo
field_switch_delay(800, 1500) msDelay when switching between form fields

Typing algorithm: Per-character delay with random spread → 10% pause chance → 2% typo chance (nearby key → notice → backspace → retype) → Shift symbols via CDP Input.dispatchKeyEvent for isTrusted=true.

Scrolling
ParameterDefaultEffect
scroll_delta_base(80, 130) pxScroll distance per step
scroll_accel_steps(2, 3)Acceleration phase steps
scroll_decel_steps(2, 3)Deceleration phase steps
scroll_overshoot_chance0.10Probability of overshooting
scroll_overshoot_px(50, 150) pxOvershoot distance
scroll_target_zone(0.20, 0.80)Target zone in viewport
scroll_settle_delay(300, 600) msDelay after reaching target

Scroll algorithm: Accelerate (2-3 steps, 80-100px) → cruise (80-130px, burst into 20-40px wheel chunks at 8-20ms intervals) → decelerate (2-3 steps, 60-90px) → 10% overshoot chance with correction.

Show full SKILL.md (304 more words)Show less
Click Behavior
ParameterDefaultEffect
click_aim_delay_input(60, 140) msDelay before clicking input elements
click_aim_delay_button(80, 200) msDelay before clicking buttons
click_hold_input(40, 100) msHold duration on inputs
click_hold_button(60, 150) msHold duration on buttons
click_input_x_range(0.05, 0.30)Click position within input (left side)
Idle Behavior
ParameterDefaultEffect
idle_between_actionsFalseEnable micro-movements between actions
idle_between_duration(0.3, 0.8) secIdle duration between actions
idle_drift_px3 pxRandom cursor drift during idle
idle_pause_range(300, 1000) msIdle pause duration
initial_cursor_x(400, 700) pxStarting cursor X (address bar area)
initial_cursor_y(45, 60) pxStarting cursor Y (address bar area)
Presets
PresetTypingAim DelayIdle BetweenUse Case
default70±40ms60-140msNoNormal human speed
careful100±50ms80-180msYes (0.4-1.0s)Slower, more deliberate

Pitfalls

  • Humanize requires the wrapper. Connecting via CDP without the wrapper loses humanization — only fingerprint patches work over raw CDP.
  • ElementHandle objects bypass humanization in Playwright. Use page.click(selector) or page.locator(selector).* — avoid query_selector() handles.
  • page.fill() with humanize clears existing content and types character by character. This is intentional but slower than raw fill().
  • Typing speed profiling exists. Some sites measure ms-between-keystrokes. Use careful preset or increase typing_delay for suspicious targets.
  • Scroll-to-element is automatic. On click/hover, the element is scrolled into view with human scroll before interaction.
  • CDP Isolated Worlds are used for stealth DOM queries. This prevents monkey-patch detection in the main JavaScript context.

Verification

  1. Test against https://deviceandbrowserinfo.com — should show 24/24 behavioral signals passed.
  2. Compare reCAPTCHA v3 scores with and without humanize=True — humanize should increase score by 0.2-0.4.
  3. Use browser DevTools Performance tab to record a session — mouse events should show realistic timing curves, not instant jumps.
  4. Verify Input.dispatchKeyEvent events have isTrusted: true in the event listener.
  • stealth-browser-launch — Launch the patched Chromium binary with C++ fingerprint modifications.
  • tls-fingerprint-impersonation — TLS/JA4 fingerprint spoofing for HTTP-level evasion.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/humanize-automation of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Humanize Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Humanize Automation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Humanize Automation this skilluphiago/recon-skills1.3k—~2.2kAutomated safety check: PassMIT
HumanizerAzure-Samples/interview-coach-agent-framework17237 repos~5.8kAutomated safety check: PassMIT
Avoid AI Writingconorbronsdon/avoid-ai-writing4.9k3 repos~8.1kAutomated safety check: PassMIT
User-Facing Text Cleanupguillaumemeyer/watermarks-remover23k—~3.5kAutomated safety check: PassMIT
Install Anti Sloptrycompai/crm11k1 repos~881Automated safety check: PassMIT
Stop SlopXe/site7318 repos~423Automated safety check: PassMIT

Similar skills

  • Humanizer

    Azure-Samples/interview-coach-agent-framework

    Official

    Remove signs of AI-generated writing from text. An agent skill from Azure-Samples/interview-coach-agent-framework.

    172 GitHub starsUsed in 37 repos~5.8k tokens
    Writing & ContentAuto-check passed
  • Avoid AI Writing

    conorbronsdon/avoid-ai-writing

    Audit and rewrite content to remove AI writing patterns ("AI-isms").

    4.9k GitHub starsUsed in 3 repos~8.1k tokens
    Writing & ContentAuto-check passed
  • User-Facing Text Cleanup

    guillaumemeyer/watermarks-remover

    Audits prose for invisible Unicode characters and rewrites it while keeping facts, citations, code and required disclosures unchanged and the writer's voice intact.

    23k GitHub stars~3.5k tokensUpdated yesterday
    Writing & ContentAuto-check passed
  • Install Anti Slop

    trycompai/crm

    Install and configure the anti-slop Oxlint plugin in a local TypeScript or JavaScript repository.

    11k GitHub starsUsed in 1 repo~881 tokens
    Writing & ContentAuto-check passed
  • Stop Slop

    Xe/site

    Remove AI writing patterns from prose. An agent skill from Xe/site.

    731 GitHub starsUsed in 8 repos~423 tokens
    Writing & ContentAuto-check passed
  • Chinese Text Humanizer

    op7418/Humanizer-zh

    Edits Chinese articles, comments and documents to remove filler, repetition and template phrasing while keeping the facts, the level of certainty and the author's voice.

    19k GitHub stars~2k tokensUpdated 14 days ago
    Writing & ContentAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Humanize Automation

What does Humanize Automation do?

Human-like mouse, keyboard and scroll behavior for behavioral bot bypass. Humanize Automation is an agent skill from uphiago/recon-skills. Human-like mouse, keyboard and scroll behavior for behavioral bot bypass.

When should I use Humanize Automation?

Humanize Automation fits situations like: tasks that involve Humanizing AI text.

How do I install Humanize Automation in Claude Code?

Run `npx skills add uphiago/recon-skills --skill humanize-automation -a claude-code`. Or copy the skill folder (recon/humanize-automation in uphiago/recon-skills) into .claude/skills/humanize-automation in your project. Claude Code loads it when a task matches its description.

How do I install Humanize Automation in Codex?

Run `npx skills add uphiago/recon-skills --skill humanize-automation -a codex`. Or copy the skill folder (recon/humanize-automation in uphiago/recon-skills) into .agents/skills/humanize-automation in your project. Codex loads it when a task matches its description.

Can I use Humanize Automation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill humanize-automation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/humanize-automation, .gemini/skills/humanize-automation, .github/skills/humanize-automation and .opencode/skills/humanize-automation in your project.

What does Humanize Automation need to run?

Going by SKILL.md and its folder, Humanize Automation needs the command-line tools its instructions call (pip). Our summary lists: Python 3. Compatibility (from SKILL.md): Requires python3.

Does Humanize Automation access the network?

SKILL.md names 1 domain. In commands or code: deviceandbrowserinfo.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Humanize Automation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Humanize Automation use?

Humanize Automation is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Humanize Automation use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Humanize Automation?

Skills that share tags, products or a category with Humanize Automation: Humanizer (Azure-Samples/interview-coach-agent-framework, 172 stars), Avoid AI Writing (conorbronsdon/avoid-ai-writing, 4.9k stars), User-Facing Text Cleanup (guillaumemeyer/watermarks-remover, 23k stars) and Install Anti Slop (trycompai/crm, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Humanize Automation?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.