skills/ruvnet/ruflo/browser-auth-flow/Gen Agent Trust Hub

browser-auth-flow

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data by loading and interacting with third-party websites during the authentication probe.
  • Ingestion points: Third-party web pages, login forms, external redirects, and cookies are read via mcp__plugin_ruflo-core_ruflo__browser_eval and related browser actions.
  • Boundary markers: The documentation mentions a quarantine step and data validation gates (aidefence_is_safe from related skills), though strict mechanical delimiters within this markdown profile itself are not explicitly defined.
  • Capability inventory: The skill has access to extensive browser automation tools (browser_eval, browser_open, browser_click) and file management utilities (Write, Bash).
  • Sanitization: The workflow indicates content is passed through aidefence_scan to filter and redact sensitive structures or unexpected commands before it returns to the model runtime context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — browser-auth-flow