Agent skill

Stealth Browser Launch

by uphiago in uphiago/recon-skills

Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass.

MITAuto-check passedSecurity

Install Stealth Browser Launch

skills CLI
$ npx skills add uphiago/recon-skills --skill stealth-browser-launch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills stealth-browser-launch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/stealth-browser-launch .claude/skills/stealth-browser-launch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stealth-browser-launch
GitHub stars
1.3k
Token cost
~2.2k tokens
SKILL.md length
540 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass.

  • Works in 7 steps: Basic Stealth Launch → Persistent Identity → Headed Mode for Maximum Stealth → …
  • Security work in your project
  • SKILL.md covers When to Use, Prerequisites, Quick Start and Procedure, plus 4 more sections
  • Calls pip, python3 and docker; reaches browserscan.net and demo.fingerprint.com

What it does

Stealth Browser Launch is an agent skill from uphiago/recon-skills. Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, httpx, nuclei, python3

It sits in Security. It works with C++ and Playwright. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/stealth-browser-launch”

Requirements

  • Python 3
  • Docker
  • Compatibility (from SKILL.md): Requires curl, httpx, nuclei, python3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Basic Stealth Launch
  2. Persistent Identity
  3. Headed Mode for Maximum Stealth
  4. Fingerprint Customization
  5. Persistent Profile
  6. Multi-Identity via CDP Multiplexer
  7. Anti-Bot Font Setup

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip
    • python3
    • docker
    • apt
    • playwright

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • browserscan.net
    • demo.fingerprint.com
    • antcpt.com
    • deviceandbrowserinfo.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, httpx, nuclei, python3

    From compatibility in the SKILL.md frontmatter.

Context cost

Stealth Browser Launch loads about 2.2k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 540 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 540 words, ~2,155 tokens.

Download SKILL.mdSave it as .claude/skills/stealth-browser-launch/SKILL.md (or your agent's skills folder).
name
stealth-browser-launch
description
Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass.
compatibility
Requires curl, httpx, nuclei, python3
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, stealth, browser, anti-bot, fingerprint, chromium, playwright
category
recon
related_skills
humanize-automation, tls-fingerprint-impersonation, http2-header-impersonation, proxy-geoip-automation

Stealth Browser Launch

Launch a patched Chromium binary with C++ source-level fingerprint modifications that bypass anti-bot detection. The binary spoofs canvas, WebGL, audio, GPU, screen, WebRTC, network timing, and automation signals at the binary level — not via JavaScript injection or config patches that break with Chrome updates. Passes Cloudflare Turnstile, reCAPTCHA v3 (0.9 score), FingerprintJS, BrowserScan, and 30+ detection sites.

When to Use

  • Target blocks curl/httpx/nuclei with Cloudflare, Akamai, DataDome, or Kasada.
  • Need full browser JavaScript execution for form submission, login, or XSS testing.
  • Target returns 403 on all unauthenticated requests even with proper headers.
  • Need to access reCAPTCHA-protected endpoints without solving CAPTCHAs.
  • Running automated recon behind residential proxies — stealth browser prevents IP+UA correlation.

Prerequisites

  • terminal with python3 and pip.
  • playwright installed: pip install playwright && playwright install-deps chromium.
  • Residential proxy (datacenter IPs are reputation-blocked regardless of browser fingerprint).
  • Optional: cloakbrowser[geoip] for automatic timezone/locale resolution from proxy exit IP.

Quick Start

bash
pip install cloakbrowser
python3 -c "
from cloakbrowser import launch
browser = launch()
page = browser.new_page()
page.goto('https://target.com')
print(page.title())
browser.close()
"

Procedure

Phase 1 — Basic Stealth Launch

The binary auto-generates a random fingerprint seed per launch. No flags needed for basic stealth:

python
from cloakbrowser import launch

browser = launch(
    headless=True,
    proxy="http://user:pass@residential-proxy:port",
    geoip=True,    # auto-detect timezone/locale from proxy exit IP
)
page = browser.new_page()
page.goto("https://target.com")
# Standard Playwright API from here
page.locator("input[name='username']").fill("test")
page.locator("button[type='submit']").click()
browser.close()
Phase 2 — Persistent Identity

Use a fixed fingerprint seed when revisiting the same target to appear as a returning visitor:

python
browser = launch(
    proxy="http://user:pass@residential-proxy:port",
    geoip=True,
    args=["--fingerprint=42069"],  # fixed seed = same fingerprint every launch
)
Phase 3 — Headed Mode for Maximum Stealth

Some sites detect headless even with C++ patches. Run headed with a virtual display:

bash
# Start virtual display
Xvfb :99 -screen 0 1920x1080x24 &
export DISPLAY=:99
python
browser = launch(
    headless=False,  # real rendering
    proxy="http://residential-proxy:port",
    geoip=True,
    humanize=True,   # human-like mouse/keyboard/scroll
)
Phase 4 — Fingerprint Customization

Override specific fingerprint values to match a target environment:

python
browser = launch(stealth_args=False, args=[
    "--fingerprint=42069",
    "--fingerprint-platform=windows",
    "--fingerprint-gpu-vendor=NVIDIA Corporation",
    "--fingerprint-gpu-renderer=NVIDIA GeForce RTX 3060/PCIe/SSE2",
    "--fingerprint-hardware-concurrency=16",
    "--fingerprint-device-memory=16",
    "--fingerprint-screen-width=2560",
    "--fingerprint-screen-height=1440",
    "--fingerprint-timezone=America/Sao_Paulo",
    "--fingerprint-locale=pt-BR",
    "--fingerprint-webrtc-ip=auto",
    "--fingerprint-noise=false",  # disable noise for FingerprintJS ML bypass
])
Phase 5 — Persistent Profile

Maintain cookies and localStorage across sessions to bypass "first-visit" challenges:

python
from cloakbrowser import launch_persistent_context

ctx = launch_persistent_context(
    "./target-profile",
    headless=False,
    proxy="http://residential-proxy:port",
    geoip=True,
)
page = ctx.new_page()
page.goto("https://target.com")
# Session persists across restarts
ctx.close()
Phase 6 — Multi-Identity via CDP Multiplexer

Run multiple browser identities from a single container using cloakserve:

bash
docker run -d --name cloak -p 127.0.0.1:9222:9222 cloakhq/cloakbrowser cloakserve
python
from playwright.sync_api import sync_playwright

pw = sync_playwright().start()

# Each unique fingerprint seed spawns separate Chrome process with independent identity
b1 = pw.chromium.connect_over_cdp("http://localhost:9222?fingerprint=11111")
b2 = pw.chromium.connect_over_cdp("http://localhost:9222?fingerprint=22222")

# Full identity control via query params
b3 = pw.chromium.connect_over_cdp(
    "http://localhost:9222?fingerprint=33333"
    "&timezone=America/New_York&locale=en-US&platform=windows"
    "&hardware-concurrency=4&device-memory=8"
)

# Each browser has independent cookies, localStorage, canvas noise
Phase 7 — Anti-Bot Font Setup

For aggressive sites (Kasada, Akamai) that check canvas emoji rendering:

bash
apt install -y fonts-noto-color-emoji fonts-freefont-ttf fonts-unifont \
    fonts-ipafont-gothic fonts-wqy-zenhei fonts-tlwg-loma-otf

For CreepJS font enumeration evasion, install Windows fonts:

bash
# Copy from Windows machine: C:\Windows\Fonts\
mkdir -p ~/.local/share/fonts/windows
cp /path/to/windows/fonts/SegoeUI*.ttf ~/.local/share/fonts/windows/
fc-cache -f

# Then launch with:
browser = launch(args=["--fingerprint-fonts-dir=/home/user/.local/share/fonts/windows"])

Fingerprint Flag Reference

FlagDefaultWhat it controls
--fingerprint=SEEDRandom 5-digitMaster seed for canvas/WebGL/audio/fonts
--fingerprint-platformwindows/macosnavigator.platform, UA OS, GPU pool
--fingerprint-gpu-vendorAutoWebGL UNMASKED_VENDOR_WEBGL
--fingerprint-gpu-rendererAutoWebGL UNMASKED_RENDERER_WEBGL
--fingerprint-hardware-concurrency8navigator.hardwareConcurrency
--fingerprint-device-memory8navigator.deviceMemory
--fingerprint-screen-width1920/1440Screen width
--fingerprint-screen-height1080/900Screen height
--fingerprint-timezone—IANA timezone
--fingerprint-locale—BCP 47 locale
--fingerprint-webrtc-ip—WebRTC ICE IP (auto for proxy exit IP)
--fingerprint-noise=falsetrueDisable canvas/WebGL/audio noise
--fingerprint-fonts-dir—Target platform fonts path
--fingerprint-windows-font-metrics—Align font metrics to Windows (v148+)
--fingerprint-storage-quotaAutoStorage quota in MB
--fingerprint-taskbar-height48/95/0Taskbar height spoofing
Show full SKILL.md (174 more words)Show less

Pitfalls

  • Datacenter IPs get blocked regardless of browser fingerprint. Always use residential proxies.
  • page.wait_for_timeout() leaks CDP traffic that reCAPTCHA detects. Use time.sleep() instead.
  • Puppeteer sends more CDP traffic than Playwright. Use Playwright for reCAPTCHA-heavy targets.
  • Missing fonts cause canvas hash mismatches on Kasada/Akamai. Install the font packages listed in Phase 7.
  • --fingerprint-noise=false can cause ML-based detection on FingerprintJS. Only disable noise when specifically blocked by it.
  • Headless mode can be detected even with C++ patches. Use headed mode (headless=False) for maximum stealth on aggressive sites.
  • Binary auto-updates are cached ~24h. Pin with browser_version= if you need reproducibility.

Verification

  1. Test against https://browserscan.net — all 4 bot checks should show NORMAL.
  2. Test against https://demo.fingerprint.com/playground — should not show "nodriver" or "bot" detection.
  3. Test against reCAPTCHA v3: https://antcpt.com/eng/information/demo-form/recaptcha-3-test-score.html — score should be ≥ 0.7.
  4. Test against https://deviceandbrowserinfo.com — isBot should be false with 0 true flags.
  5. Verify navigator.webdriver is false with page.evaluate("navigator.webdriver").
  • humanize-automation — Human-like mouse/keyboard/scroll for behavioral bypass.
  • tls-fingerprint-impersonation — TLS/JA4 fingerprint spoofing at the HTTP client level.
  • http2-header-impersonation — Browser-specific HTTP/2 pseudo-header ordering and SETTINGS frames.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/stealth-browser-launch of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Stealth Browser Launch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Stealth Browser Launch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Stealth Browser Launch this skilluphiago/recon-skills1.3k—~2.2kAutomated safety check: PassMIT
ONNX Runtime Shape Inference Safety Auditmicrosoft/onnxruntime22k—~3.3kAutomated safety check: PassMIT
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Doc CommentsMichaelGrafnetter/DSInternals2k—~1.2kAutomated safety check: PassMIT
Harness Design Fuzzingprovos/ironcurtain613—~5.7kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

    22k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Doc Comments

    MichaelGrafnetter/DSInternals

    Ensure that C and C++/CLI types are documented with XML comments and follow best practices for documentation.

    2k GitHub stars~1.2k tokensUpdated 25 days ago
    SecurityAuto-check passed
  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    613 GitHub stars~5.7k tokensUpdated today
    SecurityAuto-check passed
  • Dast Automation

    hardw00t/ai-security-arsenal

    Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

    104 GitHub stars~2.2k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Stealth Browser Launch

What does Stealth Browser Launch do?

Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass. Stealth Browser Launch is an agent skill from uphiago/recon-skills. Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass.

When should I use Stealth Browser Launch?

Stealth Browser Launch fits situations like: security work in your project.

How do I install Stealth Browser Launch in Claude Code?

Run `npx skills add uphiago/recon-skills --skill stealth-browser-launch -a claude-code`. Or copy the skill folder (recon/stealth-browser-launch in uphiago/recon-skills) into .claude/skills/stealth-browser-launch in your project. Claude Code loads it when a task matches its description.

How do I install Stealth Browser Launch in Codex?

Run `npx skills add uphiago/recon-skills --skill stealth-browser-launch -a codex`. Or copy the skill folder (recon/stealth-browser-launch in uphiago/recon-skills) into .agents/skills/stealth-browser-launch in your project. Codex loads it when a task matches its description.

Can I use Stealth Browser Launch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill stealth-browser-launch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stealth-browser-launch, .gemini/skills/stealth-browser-launch, .github/skills/stealth-browser-launch and .opencode/skills/stealth-browser-launch in your project.

What does Stealth Browser Launch need to run?

Going by SKILL.md and its folder, Stealth Browser Launch needs the command-line tools its instructions call (pip, python3, docker, apt and playwright). Our summary lists: Python 3; Docker. Compatibility (from SKILL.md): Requires curl, httpx, nuclei, python3.

Does Stealth Browser Launch access the network?

SKILL.md names 4 domains. In commands or code: browserscan.net, demo.fingerprint.com, antcpt.com and deviceandbrowserinfo.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Stealth Browser Launch safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Stealth Browser Launch use?

Stealth Browser Launch is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Stealth Browser Launch use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Stealth Browser Launch?

Skills that share tags, products or a category with Stealth Browser Launch: ONNX Runtime Shape Inference Safety Audit (microsoft/onnxruntime, 22k stars), Code Audit (3stoneBrother/code-audit, 893 stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars) and Doc Comments (MichaelGrafnetter/DSInternals, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Stealth Browser Launch?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.