Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/anusoft/ultrastealth/claude-mdgit clone --depth 1 https://github.com/anusoft/ultrastealthWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/anusoft/ultrastealth/claude-md)<a href="https://agentmods.dev/instructions/anusoft/ultrastealth/claude-md"><img src="https://agentmods.dev/badge/instructions/anusoft/ultrastealth/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02327 | $0.02327 |
| Opus 5 | $0.01163 | $0.01163 |
| Sonnet 5 | $0.00465 | $0.00465 |
| Haiku 4.5 | $0.00233 | $0.00233 |
Grade C, and why
ultrastealth CLAUDE.md scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
`curl -fsSL https://raw.githubusercontent.com/anusoft/ultrastealth/main/install.sh | bash` Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
`curl -fsSL https://raw.githubusercontent.com/anusoft/ultrastealth/main/install.sh | bash` How it starts
The opening of the file, as written. The whole thing — 142 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Ultrastealth MCP Handoff
Current Work
- MCP profile selection is implemented on
browser_navigateandbrowser_restart. - Both tools accept
profile_directory,user_data_dir, andrunner. - When a requested profile differs from the active browser profile, MCP restarts the browser with the requested profile.
- Env or tool profile requests disable temporary-profile fallback so the tool does not silently use the wrong Chrome/Chromium profile.
- Default-profile launch still retries once with a temporary profile when no explicit profile is requested, preserving one-shot navigation when normal Chrome locks the default profile.
Warm Daemon + Fast CLI
- A standalone daemon (
ultrastealth daemon start) owns one warm, persistent-profile Chrome; theultrastealth/usCLI, the MCP server, andconnect()scripts all attach to it over a Unix socket. Only the daemon holds the CDP connection (no multi-connection churn). - Shared engine
browser_core.pyis the single implementation of every op (navigate/snapshot/click/type/wait/get/is/evaluate/batch/…).daemon.pyserves it as JSON-RPC;client.pyis the client +connect();cli.pyis the CLI; the MCP server gainedbrowser_batch+browser_snapshotand auto-routes to the daemon when its socket exists (opt out withULTRASTEALTH_MCP_NO_DAEMON=1). - Speed levers: warm reuse (no cold start), stable
eNsnapshot refs +--snapshot-after, andbrowser_batch(N steps → 1 call). The stealth launch path infetcher.pyis unchanged for the daemon, so bot-detection parity is preserved. (Note: the JSbypasses/*.jschain this line used to reference no longer exists — see "Benchmark & Stealth Posture" below.) - Socket/pid/log live under
ULTRASTEALTH_DAEMON_DIR(default~/.ultrastealth); the socket auto-relocates to a short temp path if that dir would exceed the AF_UNIX length limit.ULTRASTEALTH_IDLE_TIMEOUTcontrols keep-warm (0= never close). - Agent playbook + full command list: the bundled
fast-browserskill (skills/fast-browser/).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 142 lines · 2,327 tokens per session scan C ea42bf14ccae
ultrastealth CLAUDE.md is an instructions file published in the GitHub repository anusoft/ultrastealth (0 stars, last pushed 1mo ago), licensed MIT. It adds 2,327 tokens to every session, about $0.0116 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
Browser4 CLAUDE.md
Claude Code instructions for platonai/Browser4, covering browser4 — project context for claude, architecture, key dispatch chain (cli → browser), batch commands and e2e test structure.
fix-quera AGENTS.md
Instructions for AlirezaKeshavarz83/fix-quera, covering agent guidance, project shape, visual style, quera page data findings and compatibility findings.
fast-browser CLAUDE.md
Claude Code instructions for m4ttstack/fast-browser, covering fast browser plugin, where a change belongs, fork branch: use fast-browser-runtime, releasing a new runtime and re-pinning this repo: use the script.
sendblue-browser-use AGENTS.md
Instructions for sendblue-api/sendblue-browser-use, covering agents.md — sendblue-browser-use, what this repo is, setup, common commands and health (no auth).
sniff AGENTS.md
AGENTS.md instructions for Aboudjem/sniff, covering agents.md: sniff, what this repo is, how an agent should use sniff, handling the playwright setup gate and finding output schema.
browser_oxide AGENTS.md
AGENTS.md instructions for yfedoseev/browser_oxide, covering browseroxide — conventions for ai coding assistants, build & test, architecture, key conventions and where to read more.