Anti-Detect Browser Skills: Claude Code Plugin for AntiBrow
Launch and manage anti-detect browsers with unique real-device fingerprints for multi-account operations, web scraping, ad verification, and AI agent automation.
At a glance
- What is it?
- A set of four Claude Code skills that teach an AI agent to launch and control AntiBrow, a modified-Chromium anti-detect browser with kernel-level fingerprinting. The skills cover isolation testing, SDK scripting in JavaScript and Python, MCP agent-driven browsing, and site-specific multi-account scraping.
- Who is it for?
- Engineers building QA pipelines to test their own bot-detection, ad-verification teams checking geo-pricing, and developers giving an AI agent a persistent browser identity will find the four skills useful out of the box. The MCP skill removes almost all boilerplate: the agent calls tools rather than writing code.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 34 days ago.
- What is it written in?
- GitHub does not report a main language for this repository.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem: headless detection and fragmented multi-account tooling
Anti-bot systems have moved well past checking whether JavaScript sees `navigator.webdriver`. They cross-reference canvas hashes, WebGL renderer strings, audio context fingerprints, Web Worker output, and TLS ClientHello bytes. A headless Chromium with a stealth plugin patches the JavaScript layer, which leaves property descriptors and getter chains that detectors read as tells. Operators running multiple accounts for ad verification, QA, or data collection face a second problem: there is no shared profile format, so a profile created in Node cannot be reused from Python or from a desktop client.
This repository addresses both by packaging AntiBrow access as Claude Code skills. AntiBrow ships a modified Chromium build, not a script layer. Canvas, WebGL, WebGPU, audio, `navigator`, screen geometry, and timezone are answered inside C++ and Blink, so there is no injected script to find and no descriptor out of place. The four skills teach Claude how to drive that browser.
Kernel-level fingerprinting: what AntiBrow actually does
AntiBrow's core claim is that each profile presents one coherent persona sampled from a single real machine across 30 categories and more than 500 parameters, frozen at profile creation and replayed on every subsequent launch. The README contrasts this with independently randomized values, which contradict each other: an AMD GPU renderer next to an Intel vendor string, or a 1.0 device-pixel-ratio on a 1536 by 864 screen.
Several consistency properties follow from this design. Web Workers return the same identity values as the main thread, which matters because detectors re-check inside workers precisely because partial JavaScript overrides miss that scope. Canvas and WebGL reads are deterministic per profile across relaunches: a hash that changes on every read, or an OffscreenCanvas that disagrees with the 2D canvas, are both treated as flags. The TLS ClientHello and HTTP/2 and HTTP/3 behavior match a genuine Chrome build's because the kernel is one.
Timezone, locale, and WebRTC follow the proxy exit IP. The proxy credentials are answered inside the network stack using HTTP 407 and SOCKS5 RFC 1929 negotiation, so nothing shows up under `chrome://extensions`.
The README suggests running public detection suites to verify a setup: CreepJS, browserleaks.com/canvas, pixelscan.net, and `npx liarjs` for around 40 cross-layer consistency rules that can run in CI.
Installing the skills and a first SDK call
The recommended path installs all four skills together as a Claude Code plugin:
/plugin marketplace add antibrow/anti-detect-browser-skills
/plugin install anti-detect-browser-skills@antibrowIndividual skills can also be added through the `skills` CLI:
npx skills add https://github.com/antibrow/anti-detect-browser-skills --skill anti-detect-browserThe SDK itself installs separately from the skills:
npm install [email protected] playwright-coreor for Python:
pip install antibrow==0.9.0Both SDKs share `~/.anti-detect-browser/` for profile storage, so a profile created in Node is launchable from Python with the same fingerprint. The README notes that `playwright install` is never needed because AntiBrow drives its own kernel.
A minimal JavaScript launch looks like this:
const ab = new AntiDetectBrowser({ key: process.env.ANTI_DETECT_BROWSER_KEY })
const { page, browser } = await ab.launch({ profile: 'shopper-01' })The equivalent in Python:
from antibrow import launch
browser = launch(profile="shopper-01")
page = browser.new_page()The README pins the SDK versions in the install commands. It advises pinning `[email protected]` in Node rather than pulling latest.
The four skills and what each covers
The multi-account-isolation skill is described as the starting point for checking whether a setup actually holds. It documents eleven concrete checks: timezone against exit IP, WebRTC candidate addresses, canvas stability across relaunches, worker versus main-thread agreement, single GPU identity across WebGL, WebGL2, and WebGPU, and absence of duplicate personas across a fleet.
The anti-detect-browser skill covers the SDK, profile management, fingerprint configuration, proxy assignment, kernel updates, Docker deployment, and the REST API.
The browser-mcp-agent skill configures MCP server mode. In this mode an AI agent such as Claude calls tools to launch and control the browser without writing any application code. The skill supports Claude, GPT, and other agents that implement the MCP protocol.
The multi-account-scraping skill runs the same task across many accounts in parallel, each with its own profile, fingerprint, and exit IP. The README states it handles sites that require a session or that answer plain HTTP requests with a captcha, and that it returns JSON with no selectors to write. It lists Amazon, Walmart, Google, DuckDuckGo, Reddit, X, Medium, Yelp, Indeed, Hacker News, GitHub, PyPI, and npm as supported targets. It also covers writing a new adapter and describes a domain allowlist with SHA-256 pinning for third-party adapters used on profiles holding live logins.
Platform coverage and what is not yet supported
AntiBrow supports Windows 10 and 11 x64, macOS 12 and later on both Apple Silicon and Intel as a universal build, Linux x64 with glibc, Linux arm64 with glibc as a separate kernel that auto-selects on the CPU, and Docker on both linux/amd64 and linux/arm64 running headful under Xvfb. Linux with musl libc, which includes Alpine, is listed as not yet supported.
This is a real constraint for teams that run containers on Alpine-based images. A glibc-based image such as Debian or Ubuntu will work, but an Alpine base will not without a compatibility layer.
A second limitation the README is explicit about: it lists the layers browser isolation cannot cover. Profile isolation does not prevent the server from correlating behavior patterns, billing events, or application-level identifiers. The skills documentation for multi-account-isolation includes checks that call out which layers isolation cannot reach at all.
The REST API surface and the exact authentication flow for the MCP server are documented in the AntiBrow product documentation rather than in this repository. Engineers who need to understand rate limits, credential rotation, or per-profile billing should consult that documentation directly.
Alternative approach: Playwright with a stealth plugin
The direct alternative is Playwright with a community stealth plugin such as playwright-extra and puppeteer-extra-plugin-stealth. This combination is entirely open source, requires no commercial account, and covers a wide range of common fingerprinting vectors through JavaScript overrides.
The trade-off the README states directly: stealth plugins patch from the JavaScript layer. They override getters and shim `navigator`, and anti-bot vendors have been identifying those patches for years because the patch itself is detectable as a tell. Web Worker scope and TLS behavior are beyond what any JavaScript override can reach.
For teams whose detection targets do not use cross-layer consistency checks or Worker re-reads, a stealth plugin may be sufficient and costs nothing. For teams testing against hardened detection stacks or running at production scale where a false negative has commercial consequences, the kernel-level approach matters.
Maintenance and licensing
The repository is not archived. The last push was on 2026-08-28, which is one month before this writing. The skills files carry an MIT license, which permits use, modification, and distribution without restriction.
The MIT license covers the Claude Code skills in this repository, not the AntiBrow browser kernel they wrap. The AntiBrow commercial terms govern the actual browser. The README does not reproduce those terms; they are at the AntiBrow product site. Teams deploying in production should verify whether their use case falls within the AntiBrow free tier or requires a paid plan.
Upgrade cost is low for the skills themselves: `/plugin update` brings in the latest skill content. The SDK packages are pinned in the install commands with explicit version numbers, so updates require a deliberate version bump rather than pulling latest automatically. The README notes that the kernel is separate from the npm and PyPI packages and updates independently.
Editorial conclusion
Engineers building QA pipelines to test their own bot-detection, ad-verification teams checking geo-pricing, and developers giving an AI agent a persistent browser identity will find the four skills useful out of the box. The MCP skill removes almost all boilerplate: the agent calls tools rather than writing code. Developers who need to operate identities they do not own or who want to bypass platform terms of service should read the Acceptable Use section of the AntiBrow documentation before proceeding; the skills themselves do not enforce use limits. Before adopting, verify that the antibrow commercial license terms match your deployment context, because the MIT license here covers only the skill files, not the AntiBrow kernel they drive.
Frequently asked questions
What does anti-detect-browser-skills add beyond just installing AntiBrow?
The skills teach Claude Code how to use AntiBrow's SDK and MCP interface. Without the skills, an agent would have no knowledge of the API surface, profile conventions, proxy configuration, or available site-specific scrapers. The skills package that knowledge as loadable context rather than requiring it in every conversation.
Can the multi-account-scraping skill be used on any website?
The README lists a specific set of supported sites and describes how to write a new adapter for additional targets. It also describes a domain allowlist and SHA-256 pinning mechanism designed to keep third-party adapters safe when running on profiles that hold live logins.
Does the browser-mcp-agent skill require writing code?
The README describes the MCP server mode as a way to let an AI agent launch and control the browser via tool calls with no code to write. The agent issues tool calls; the MCP server translates them into browser operations.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/antibrow-anti-detect-browser-skills)