# Browser Act

> Browser Act is an unverified skill from browser-act. Anomity scores its risk at 95 out of 100 (critical). It matches 1 dangerous capability combination.

- **Canonical URL:** https://catalog.anomity.ai/skill/browser-act
- **Kind:** Skill
- **Publisher:** browser-act
- **Trust level:** unknown
- **Risk score:** 95/100 (critical)
- **Website:** https://github.com/browser-act
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/skill/browser-act

## Description

A CLI for browser automation that includes stealth features and CAPTCHA solving, aimed at driving sites that actively resist automation.

It runs as a command-line tool controlling a browser and reaching the network, so it declares shell execution, browser control, and outbound network — a combination that scores high in this catalog. CAPTCHA solving is worth naming plainly: it exists to defeat a control the site operator deliberately put in place, and building it into an agent stack is a choice about what that agent is for.

## Why it scored 95

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Unknown publisher | +20 | critical |  |
| 1 high-risk capability: shell:execute | +10 | high |  |
| Data exfiltration risk (high) | +15 | high | Shell execution combined with outbound network access can exfiltrate arbitrary data from the machine. |

Clamped result: **95/100**, band **critical**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `shell:execute` | Shell execution | Can run arbitrary shell commands. Combined with network access this becomes effectively a remote shell. |
| `browser:control` | Browser control | Drives a browser session. Combined with credential access can impersonate the user on web services. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |

## Dangerous combinations matched

### Data exfiltration risk (high)

Shell execution combined with outbound network access can exfiltrate arbitrary data from the machine.

Capabilities: `shell:execute`, `network:outbound`

## Related skills

- [AI Research Reproduction](https://catalog.anomity.ai/skill/ai-research-reproduction) — risk 100 (critical)
- [Anti-Detect Browser](https://catalog.anomity.ai/skill/anti-detect-browser) — risk 70 (high)
- [Azure Deploy](https://catalog.anomity.ai/skill/azure-deploy) — risk 45 (medium)
- [Azure Diagnostics](https://catalog.anomity.ai/skill/azure-diagnostics) — risk 45 (medium)
- [Audit Website](https://catalog.anomity.ai/skill/audit-website) — risk 40 (medium)
- [NotebookLM Skill](https://catalog.anomity.ai/skill/notebooklm-skill) — risk 40 (medium)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
