Back to plugin

Security audit

Camofox Browser

Security checks for vulnerabilities and agentic risk

Overview

This browser automation plugin is mostly coherent and disclosed, but it needs Review because its default server exposure is powerful and under-protected.

Install only if you want an agent-controllable browser server. Before running it, set CAMOFOX_BIND_HOST=127.0.0.1 for local-only access or configure CAMOFOX_ACCESS_KEY if anything beyond localhost can reach port 9377. Disable persistence or telemetry if those defaults do not match your privacy expectations, and only enable cookie import for accounts you are comfortable letting the agent use.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/windows-processes.js:17
Evidence
return cp.execFileSync(command, args, { ...options, env: windowsProcessEnvironment(), windowsHide: true });