stealth-browser-launch
Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass.
Install / Use
npx skills add uphiago/recon-skills --skill stealth-browser-launchInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
AutomationSupported Platforms
Our assessment of stealth-browser-launch
stealth-browser-launch scores 89/100 on our quality scale, 1081st of 2,750 Automation skills we index (top 40%).
Its SKILL.md is 8.4 KB long, well organised into 24 sections with 11 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so stealth-browser-launch is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
stealth-browser-launch compared with similar skills
All 4 of these similar skills score higher than stealth-browser-launch; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| stealth-browser-launch (this skill)by uphiago | 89 | 1.3k | 29d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.6k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 84.8k | today | MCP Server |
Frequently asked questions
- How do I install stealth-browser-launch?
- Run
npx skills add uphiago/recon-skills --skill stealth-browser-launch. The install tabs above show the steps for each supported agent. - Which AI agents does stealth-browser-launch work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is stealth-browser-launch safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is stealth-browser-launch still maintained?
- The repository was last updated 29 days ago, so stealth-browser-launch is actively maintained.
Skill content
View source on GitHubname: stealth-browser-launch description: Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass. version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, httpx, nuclei, python3 tags: [recon, stealth, browser, anti-bot, fingerprint, chromium, playwright] category: recon related_skills:
- humanize-automation
- tls-fingerprint-impersonation
- http2-header-impersonation
- proxy-geoip-automation
Stealth Browser Launch
Launch a patched Chromium binary with C++ source-level fingerprint modifications that bypass anti-bot detection. The binary spoofs canvas, WebGL, audio, GPU, screen, WebRTC, network timing, and automation signals at the binary level — not via JavaScript injection or config patches that break with Chrome updates. Passes Cloudflare Turnstile, reCAPTCHA v3 (0.9 score), FingerprintJS, BrowserScan, and 30+ detection sites.
When to Use
- Target blocks curl/httpx/nuclei with Cloudflare, Akamai, DataDome, or Kasada.
- Need full browser JavaScript execution for form submission, login, or XSS testing.
- Target returns 403 on all unauthenticated requests even with proper headers.
- Need to access reCAPTCHA-protected endpoints without solving CAPTCHAs.
- Running automated recon behind residential proxies — stealth browser prevents IP+UA correlation.
Prerequisites
terminalwith python3 and pip.playwrightinstalled:pip install playwright && playwright install-deps chromium.- Residential proxy (datacenter IPs are reputation-blocked regardless of browser fingerprint).
- Optional:
cloakbrowser[geoip]for automatic timezone/locale resolution from proxy exit IP.
Quick Start
pip install cloakbrowser
python3 -c "
from cloakbrowser import launch
browser = launch()
page = browser.new_page()
page.goto('https://target.com')
print(page.title())
browser.close()
"
Procedure
Phase 1 — Basic Stealth Launch
The binary auto-generates a random fingerprint seed per launch. No flags needed for basic stealth:
from cloakbrowser import launch
browser = launch(
headless=True,
proxy="http://user:pass@residential-proxy:port",
geoip=True, # auto-detect timezone/locale from proxy exit IP
)
page = browser.new_page()
page.goto("https://target.com")
# Standard Playwright API from here
page.locator("input[name='username']").fill("test")
page.locator("button[type='submit']").click()
browser.close()
Phase 2 — Persistent Identity
Use a fixed fingerprint seed when revisiting the same target to appear as a returning visitor:
browser = launch(
proxy="http://user:pass@residential-proxy:port",
geoip=True,
args=["--fingerprint=42069"], # fixed seed = same fingerprint every launch
)
Phase 3 — Headed Mode for Maximum Stealth
Some sites detect headless even with C++ patches. Run headed with a virtual display:
# Start virtual display
Xvfb :99 -screen 0 1920x1080x24 &
export DISPLAY=:99
browser = launch(
headless=False, # real rendering
proxy="http://residential-proxy:port",
geoip=True,
humanize=True, # human-like mouse/keyboard/scroll
)
Phase 4 — Fingerprint Customization
Override specific fingerprint values to match a target environment:
browser = launch(stealth_args=False, args=[
"--fingerprint=42069",
"--fingerprint-platform=windows",
"--fingerprint-gpu-vendor=NVIDIA Corporation",
"--fingerprint-gpu-renderer=NVIDIA GeForce RTX 3060/PCIe/SSE2",
"--fingerprint-hardware-concurrency=16",
"--fingerprint-device-memory=16",
"--fingerprint-screen-width=2560",
"--fingerprint-screen-height=1440",
"--fingerprint-timezone=America/Sao_Paulo",
"--fingerprint-locale=pt-BR",
"--fingerprint-webrtc-ip=auto",
"--fingerprint-noise=false", # disable noise for FingerprintJS ML bypass
])
Phase 5 — Persistent Profile
Maintain cookies and localStorage across sessions to bypass "first-visit" challenges:
from cloakbrowser import launch_persistent_context
ctx = launch_persistent_context(
"./target-profile",
headless=False,
proxy="http://residential-proxy:port",
geoip=True,
)
page = ctx.new_page()
page.goto("https://target.com")
# Session persists across restarts
ctx.close()
Phase 6 — Multi-Identity via CDP Multiplexer
Run multiple browser identities from a single container using cloakserve:
docker run -d --name cloak -p 127.0.0.1:9222:9222 cloakhq/cloakbrowser cloakserve
from playwright.sync_api import sync_playwright
pw = sync_playwright().start()
# Each unique fingerprint seed spawns separate Chrome process with independent identity
b1 = pw.chromium.connect_over_cdp("http://localhost:9222?fingerprint=11111")
b2 = pw.chromium.connect_over_cdp("http://localhost:9222?fingerprint=22222")
# Full identity control via query params
b3 = pw.chromium.connect_over_cdp(
"http://localhost:9222?fingerprint=33333"
"&timezone=America/New_York&locale=en-US&platform=windows"
"&hardware-concurrency=4&device-memory=8"
)
# Each browser has independent cookies, localStorage, canvas noise
Phase 7 — Anti-Bot Font Setup
For aggressive sites (Kasada, Akamai) that check canvas emoji rendering:
apt install -y fonts-noto-color-emoji fonts-freefont-ttf fonts-unifont \
fonts-ipafont-gothic fonts-wqy-zenhei fonts-tlwg-loma-otf
For CreepJS font enumeration evasion, install Windows fonts:
# Copy from Windows machine: C:\Windows\Fonts\
mkdir -p ~/.local/share/fonts/windows
cp /path/to/windows/fonts/SegoeUI*.ttf ~/.local/share/fonts/windows/
fc-cache -f
# Then launch with:
browser = launch(args=["--fingerprint-fonts-dir=/home/user/.local/share/fonts/windows"])
Fingerprint Flag Reference
| Flag | Default | What it controls |
|---|---|---|
| --fingerprint=SEED | Random 5-digit | Master seed for canvas/WebGL/audio/fonts |
| --fingerprint-platform | windows/macos | navigator.platform, UA OS, GPU pool |
| --fingerprint-gpu-vendor | Auto | WebGL UNMASKED_VENDOR_WEBGL |
| --fingerprint-gpu-renderer | Auto | WebGL UNMASKED_RENDERER_WEBGL |
| --fingerprint-hardware-concurrency | 8 | navigator.hardwareConcurrency |
| --fingerprint-device-memory | 8 | navigator.deviceMemory |
| --fingerprint-screen-width | 1920/1440 | Screen width |
| --fingerprint-screen-height | 1080/900 | Screen height |
| --fingerprint-timezone | — | IANA timezone |
| --fingerprint-locale | — | BCP 47 locale |
| --fingerprint-webrtc-ip | — | WebRTC ICE IP (auto for proxy exit IP) |
| --fingerprint-noise=false | true | Disable canvas/WebGL/audio noise |
| --fingerprint-fonts-dir | — | Target platform fonts path |
| --fingerprint-windows-font-metrics | — | Align font metrics to Windows (v148+) |
| --fingerprint-storage-quota | Auto | Storage quota in MB |
| --fingerprint-taskbar-height | 48/95/0 | Taskbar height spoofing |
Pitfalls
- Datacenter IPs get blocked regardless of browser fingerprint. Always use residential proxies.
page.wait_for_timeout()leaks CDP traffic that reCAPTCHA detects. Usetime.sleep()instead.- Puppeteer sends more CDP traffic than Playwright. Use Playwright for reCAPTCHA-heavy targets.
- Missing fonts cause canvas hash mismatches on Kasada/Akamai. Install the font packages listed in Phase 7.
--fingerprint-noise=falsecan cause ML-based detection on FingerprintJS. Only disable noise when specifically blocked by it.- Headless mode can be detected even with C++ patches. Use headed mode (
headless=False) for maximum stealth on aggressive sites. - Binary auto-updates are cached ~24h. Pin with
browser_version=if you need reproducibility.
Verification
- Test against
https://browserscan.net— all 4 bot checks should show NORMAL. - Test against
https://demo.fingerprint.com/playground— should not show "nodriver" or "bot" detection. - Test against reCAPTCHA v3:
https://antcpt.com/eng/information/demo-form/recaptcha-3-test-score.html— score should be ≥ 0.7. - Test against
https://deviceandbrowserinfo.com—isBotshould be false with 0 true flags. - Verify
navigator.webdriverisfalsewithpage.evaluate("navigator.webdriver").
Related Skills
humanize-automation— Human-like mouse/keyboard/scroll for behavioral bypass.tls-fingerprint-impersonation— TLS/JA4 fingerprint spoofing at the HTTP client level.http2-header-impersonation— Browser-specific HTTP/2 pseudo-header ordering and SETTINGS frames.
Related Skills
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.6k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Scrapling
84.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
