skills/ruvnet/ruflo/browser-extract/Gen Agent Trust Hub

browser-extract

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes local terminal commands via npx to fetch and store template states using @claude-flow/cli memory operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently exposes an ingestion surface by scraping untrusted third-party web content. However, it explicitly mitigates this threat surface by implementing mandatory aidefence_is_safe and aidefence_has_pii inspection steps prior to data persistence or model ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — browser-extract