browser-auth-flow
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data by loading and interacting with third-party websites during the authentication probe.
- Ingestion points: Third-party web pages, login forms, external redirects, and cookies are read via
mcp__plugin_ruflo-core_ruflo__browser_evaland related browser actions. - Boundary markers: The documentation mentions a quarantine step and data validation gates (
aidefence_is_safefrom related skills), though strict mechanical delimiters within this markdown profile itself are not explicitly defined. - Capability inventory: The skill has access to extensive browser automation tools (
browser_eval,browser_open,browser_click) and file management utilities (Write,Bash). - Sanitization: The workflow indicates content is passed through
aidefence_scanto filter and redact sensitive structures or unexpected commands before it returns to the model runtime context.
Audit Metadata