browser-record

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes the ruvector package (version 0.2.25) and the @claude-flow/cli utility using npx.
  • ruvector is a resource provided by the author (ruvnet).
  • @claude-flow/cli is a platform-associated utility used for memory storage and session indexing.
  • [COMMAND_EXECUTION]: Employs Bash commands to manage session lifecycles, including:
  • Generating time-based session IDs.
  • Creating and compacting RVF (Recording Vector Format) cognitive containers.
  • Recording trajectory steps for browser interactions.
  • [PROMPT_INJECTION]: As a browser-based primitive, the skill has an inherent surface for indirect prompt injection.
  • Ingestion points: Processes untrusted data from the browser accessibility tree, screenshots, and snapshots via mcp__claude-flow__browser_* tools.
  • Boundary markers: No explicit instruction delimiters or boundary markers are defined in this primitive.
  • Capability inventory: Has access to Bash execution, file-writing via memory storage, and browser control tools.
  • Sanitization: The skill notes that AIDefence PII scanning is available but explicitly defers the responsibility of sanitization and redaction to downstream skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 01:22 PM
Security Audit — agent-trust-hub — browser-record