⏳ This skill is pending AI review.

Scores will appear once the review pipeline completes.

version unknown

browser-fingerprint-audit

@liarjsdev⭐ 517 stars

Audit a browser fingerprint for internal contradictions with the liarjs CLI - canvas, WebGL, WebGL2, WebGPU, audio, 220 fonts, WebRTC and timezone probes, scored against the TLS/HTTP/ASN view of the same request. Use when asked to run a browser fingerprint test, see what a fingerprint looks like, check canvas or WebGL fingerprint stability, compare a spoofed profile against a real browser, or find out whether a browser profile is self-consistent.

Choose how to use this skill

You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.

1. Native installer

This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.

Do not guess an installer command or replace an existing version without reviewing the diff.

2. Complete package recommended

Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.

No complete ProSkills package is published for this listing yet.

3. Prompt-only

Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.

Need only the instruction file?

Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.

No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.

—/10

// RATINGS

⭐GitHub Stars
⭐⭐⭐⭐ 517 on GitHubGitHub ↗

Popular

🟢ProSkills Score
—
📍

Not yet listed on ClawHub or SkillsMP

// README

liarjs skills

Agent Skills for browser fingerprint testing and automation-harness QA.

Four skills that teach a coding agent to run liarjs: 40 consistency checks over 19 fingerprint probes, cross-checked against what the TLS/HTTP layer actually saw.

liarjs.dev - what the checks mean - field notes

npx skills add liarjs.dev                  # from the site's well-known endpoint
npx skills add liarjsdev/liarjs-skills     # from this repo

The skills

skilluse it when
browser-fingerprint-auditrun a browser fingerprint test and read the result: canvas, WebGL, WebGL2, WebGPU, audio, 220 fonts, WebRTC, timezone, TLS
playwright-stealth-verifycheck whether a Playwright, Puppeteer, Selenium or CDP-driven browser presents a coherent fingerprint, as an assertion in a test
fingerprint-ci-gatefail a GitHub Actions or GitLab job on a fingerprint regression, with a baseline diff
fingerprint-failure-triageturn a low score into a shortlist of things to change, by check id

Each skill is a directory with a SKILL.md following the Agent Skills format, so it works in any client that supports the standard: Claude Code, Codex, Cursor, GitHub Copilot, VS Code, Gemini CLI, OpenCode, Amp, Windsurf, Goose, Kiro and others.

Install

With the cross-agent installer:

npx skills add liarjs.dev                                               # all four, from the site
npx skills add liarjsdev/liarjs-skills                                  # all four, from this repo
npx skills add liarjsdev/liarjs-skills/skills/browser-fingerprint-audit # just one

liarjs.dev works because the site publishes this same tree at /.well-known/agent-skills/index.json (RFC 8615), so no directory site sits between you and the skills. The generator lives in the site repo as scripts/sync-skills.mjs and takes this repo as its source of truth.

Or copy a skill directory into the location your agent reads:

agentpath
Claude Code~/.claude/skills/ (user) or .claude/skills/ (project)
Codex~/.agents/skills/
GitHub Copilot~/.copilot/skills/ (user) or .github/skills/ (repo)

What the underlying tool does

A browser controls its own JavaScript. It does not control the network it connects over. liarjs reads the fingerprint inside the browser, reads the TLS/HTTP/ASN view from the edge that served the request, and reports every place the two stories disagree.

   18 / 100  Likely spoofed / bot

  x navigator.webdriver -40
    webdriver=true, the automation flag is set.
    id: webdriver

  x Worker <-> main-thread consistency -20
    A Web Worker reported different values than the main thread for userAgent, canvasHash.
    id: worker-consistency

  22 checks - 2 critical - 1 warnings - 18 clean
  edge: 203.0.113.7 - AS4058 - LAS - HTTP/2 - TLSv1.3

32 of the 40 checks need nothing but the browser (--offline). 8 compare the JavaScript story against the wire. Full list with deductions: checks.md.

Requirements: Node 22 or newer, and a local Chrome, Chromium or Edge. liarjs has zero runtime dependencies.

Scope and safety

These skills are measurement and diagnostics. They ship no evasions, profiles or proxies.

  • A scan launches its own Chrome with a fresh profile in a temp directory and deletes it when the run ends. It does not read the user's browser profile, history, cookies or saved credentials.
  • No token, login or account is involved. The skills never ask an agent to handle secrets.
  • Nothing is fetched at runtime that changes agent behaviour: the instructions and reference files are the whole content, and the npm package is version-pinned in every command.
  • Probes run on about:blank by default. The skills do not direct an agent to browse third-party sites, and they state that scan output is data to relay rather than instructions to follow.
  • Attaching to an already-running browser (--cdp) is documented as an explicit, user-requested path, not a default, because that drives a session the user owns.
  • The one outbound request in the default path is the browser under test fetching https://liarjs.dev/api/net.json, which answers with what Cloudflare saw about that request. --offline makes no request at all; --endpoint <url> points at your own deployment of that Worker. liarjs.dev does not store scans.

Related packages

packagewhat it is
liarjsthe CLI and library API these skills drive
@liarjs/collectthe 19 browser-side probes, standalone
@liarjs/checksthe 40 consistency rules as pure functions

Source for all three: github.com/liarjsdev/liarjs.

Limits worth stating up front

  • A score is not a ban prediction. It measures internal coherence. Real sites also weigh IP reputation, account age and behaviour, none of which a local scan can see.
  • Headless is detected on purpose. A stock headless run loses points, and that is the correct measurement.
  • Checks drift with Chrome. The rules are versioned with the package and reviewed per Chrome major, which is why every command here pins a version.

MIT (c) liarjs.dev

// HOW IT'S BUILT

KEY FILES

skills/browser-fingerprint-audit/SKILL.mdREADME.md

// REPO STATS

517 stars