What the probes exercise
The audit runs entirely inside the open page, so each test sees the same surface a visited site would. Cookie checks set and read back cookies to test persistence and whether cross-site contexts are blocked. Fingerprinting checks read browser-exposed signals such as canvas output, fonts, and WebGL information. API checks probe which sensitive interfaces exist, and tracking protection is judged by how cross-site requests are treated.