passoEnables secure remote access to a browser on your server for manual tasks like logins, 2FA, and captchas via a protected URL.
Install via ClawdBot CLI:
clawdbot install felipegoulu/passoGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
curl -fsSL https://raw.githubusercontent.com/felipegoulu/passo-client/main/instaCalls external URL not in known-safe list
https://getpasso.appUses known external API (expected, informational)
raw.githubusercontent.comAI Analysis
The skill installs and runs a remote browser tunnel via an external script from an unverified source, granting persistent remote access to the user's server. While the stated purpose is legitimate, the installation method bypasses security controls and the service could be used to exfiltrate data or credentials from the server environment.
Generated Mar 22, 2026
Agents can use Passo to handle merchant logins requiring 2FA on platforms like Amazon Seller Central or Shopify, where manual verification is needed. This ensures secure access without sharing credentials, streamlining inventory updates or order processing. Ideal for agencies managing multiple client accounts.
Marketing teams can bypass captchas during automated posting or ad campaign setups on Facebook or Instagram. Passo allows a human to quickly solve verification challenges remotely, reducing downtime in automated workflows. Useful for agencies running bulk social media operations.
Banks or fintech firms can utilize Passo for secure logins to regulatory portals that require 2FA, such as government tax sites or compliance databases. It enables authorized personnel to perform manual steps without exposing sensitive credentials, enhancing audit trails. Common in banking and insurance sectors.
QA engineers can access remote browsers to manually test login flows or captcha integrations in web applications. This helps simulate real-user interactions during development cycles, ensuring functionality without local setup. Beneficial for tech companies with distributed teams.
Passo operates on a monthly subscription model at $5 per month after a free trial, managed via an online dashboard. This provides recurring revenue and scales with user adoption for remote browser access needs. It targets individuals and small teams requiring occasional manual interventions.
The skill offers a 30-day free trial to attract users, then converts them to paying subscribers for continued access. This model reduces entry barriers and builds a user base that can be upsold to higher tiers or additional features. Revenue comes from trial conversions and potential premium add-ons.
Passo can partner with automation platforms or AI agent ecosystems to offer remote browser access as a value-added service. This expands reach through integrations, generating revenue via referral fees or bundled offerings. Targets businesses needing seamless manual task handling in automated workflows.
💬 Integration Tip
Install Passo on a dedicated server for stability, and use the provided URL in automation scripts to trigger human assistance only when needed, minimizing costs.
Scored Apr 19, 2026
Audited Apr 17, 2026 · audit v1.0
Self-hosted auth for TypeScript/Cloudflare Workers with social auth, 2FA, passkeys, organizations, RBAC, and 15+ plugins. Requires Drizzle ORM or Kysely for D1 (no direct adapter). Self-hosted alternative to Clerk/Auth.js. Use when: self-hosting auth on D1, building OAuth provider, multi-tenant SaaS, or troubleshooting D1 adapter errors, session caching, rate limits, Expo crashes, additionalFields bugs.
Clerk integration. Manage Users, Organizations. Use when the user wants to interact with Clerk data.
Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP outages), and component reference. Prevents 15 documented errors. Use when: API keys for users/orgs, Next.js 16 middleware filename, troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors, webhook verification, user type inconsistencies, or testing with 424242 OTP.
Start and complete WordPress.com OAuth and publish posts through the WordPress.com REST API. Use when you need to generate an authorization URL, exchange cal...
Configures Firebase Authentication — providers, security rules, custom claims, and React auth hooks
Use when auditing Go code involving authentication flows, RBAC policies, Kubernetes admission webhooks, JWT/OAuth token validation, or privilege escalation i...