browser-test

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill interacts with untrusted external websites, creating an indirect prompt injection surface (Ingestion points: browser_open, browser_get-text in SKILL.md). Mitigation is present through the mandatory use of the aidefence_is_safe safety gate which serves as a boundary marker and sanitization step before content is processed by the agent. Capability inventory includes Bash, Write, and browser_eval as specified in SKILL.md. \n- [COMMAND_EXECUTION]: The skill references framework-specific commands such as trajectory-end, rvf compact, and /ruflo-browser replay for managing test session lifecycle and artifacts. \n- [REMOTE_CODE_EXECUTION]: The skill utilizes browser_eval for executing JavaScript assertions within the browser context, which is standard functionality for automated UI testing tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 01:22 PM
Security Audit — agent-trust-hub — browser-test