1.8k Downloads
Overview
High-stealth browser automation toolkit that runs a custom patched Firefox fork (Camoufox) and curl_cffi inside an isolated pybox/distrobox container to evade advanced bot-detection and fingerprinting systems for web and API scraping.
Key Advantages
1.C++-level fingerprint spoofing in a custom Firefox build (Camoufox), avoiding detectable JavaScript-based stealth patches.
2.Containerized execution via pybox/distrobox, keeping the host system cleaner and reducing dependency conflicts.
3.Dual strategy: full browser automation for complex, JS-heavy sites plus curl_cffi for fast, TLS-fingerprinted API scraping.
4.Built-in guidance for handling Cloudflare, Datadome, Airbnb, Yelp and similar highly protected targets where standard Playwright/Selenium fail.
5.Session management utilities for persistent, reusable authenticated profiles with cookie export/import and basic login-wall detection signals.
Use Cases
- Automated interaction with heavily protected websites where you have explicit permission (e.g., your own properties or contracted data-access arrangements).
- Security research, QA, and red-team style testing of anti-bot and fingerprinting defenses in a controlled, compliant environment.
- Resilient scraping and data collection from sites that aggressively fingerprint browsers, when simpler Playwright/Selenium setups are consistently blocked.
- High-fidelity simulation of real browser fingerprints and TLS stacks for studying bot-detection behavior and evasion robustness.
- Long-lived authenticated sessions (with profiles) for dashboards or internal tools that must automatically interact with complex web frontends.
Evaluation Scores
6.3
/ 10
Reliability
6.5
Functionality
9.0
Usability
5.5
Safety
3.0
Performance
7.0
Compatibility
7.5
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
6.3/103/19/2026▼
OS: darwin-arm64LLM: moonshotai/kimi-k2.5
**Judgement:** Technically strong, niche, and highly capable stealth browser skill designed specifically to defeat modern anti-bot and fingerprinting systems. It is powerful but operationally complex and comes with significant legal, policy, and abuse-risk considerations.
**What it does well**
- Uses a *custom Firefox fork* (Camoufox) with C++-level patches for WebGL/Canvas/AudioContext etc., giving substantially deeper stealth than JS-level tools like puppeteer-stealth or undetected-chromedriver.
- Runs inside a `pybox` / `distrobox` container, which reduces impact on the host and keeps dependencies somewhat isolated.
- Integrates `curl_cffi` for API-only scraping with realistic TLS fingerprints, giving a lighter-weight option when a full browser is unnecessary.
- Provides fairly detailed operational guidance: proxy requirements (residential/mobile), headless vs headed nuances, behavioral randomization, session persistence, and troubleshooting for common Linux/Python issues.
**Key risks & concerns**
- **Misuse / Policy Risk:** The skill is explicitly optimized to bypass Cloudflare, Datadome, Airbnb, Yelp, and similar protections. Using it against third-party sites without clear, written authorization can violate terms of service, trigger legal issues (e.g., CFAA-like statutes in some jurisdictions), and breach platform policies.
- **Account & IP Risk:** Even with strong stealth, aggressive scraping can still lead to account bans, IP blacklisting, or legal complaints from target sites.
- **Operational Fragility:** Requires specific environment assumptions (pybox container, Python 3.14, residential proxies). Documentation anticipates segfaults, import issues, and library mismatches, implying a non-trivial chance of setup and runtime friction.
- **Security Handling:** While cookie/profile directories are permission-hardened, the tool deals with highly sensitive artifacts (cookies, sessions). Mishandling exports or backups can expose user accounts and internal systems.
**Recommended scenarios**
- Internal use by **experienced operators** (data engineering, security, or SRE teams) who understand browser fingerprinting, containers, and proxy management.
- **Security research, internal QA, and red teaming** of your own or contracted web properties’ anti-bot protections.
- **Compliant scraping / automation** where you have explicit permission and clear governance, and where simpler tools (Playwright, Selenium, standard headless Chrome/Firefox) have already been exhausted.
**Not recommended for**
- Casual users or teams without strong legal/compliance oversight.
- Any use that conflicts with target-site terms of service or applicable law.
In short: a sophisticated, high-evasion browser automation skill best suited for advanced, well-governed environments; high functional value but also high compliance and operational risk that must be consciously managed.
Comments (0)
No comments yet. Be the first!