skills/ruvnet/ruflo/browser-replay/Gen Agent Trust Hub

browser-replay

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session data from external trajectory files to determine its sequence of actions, which could allow malicious instructions in the recorded data to influence the agent's behavior.
  • Ingestion points: Read .../trajectory.ndjson (SKILL.md)
  • Boundary markers: None present to distinguish recorded data from instructions.
  • Capability inventory: mcp__plugin_ruflo-core_ruflo__browser_eval, Bash, and various browser interaction tools (SKILL.md).
  • Sanitization: No sanitization or validation of the recorded trajectory content is mentioned.
  • [DYNAMIC_EXECUTION]: The skill performs dynamic execution by replaying recorded arguments through browser evaluation tools.
  • Evidence: Use of mcp__plugin_ruflo-core_ruflo__browser_eval with arguments loaded directly from the trajectory file.
  • [EXTERNAL_DOWNLOADS]: Fetches and executes CLI tools directly from the NPM registry at runtime.
  • Evidence: Usage of npx -y ruvector@0.2.25 and npx -y @claude-flow/cli@latest to perform status checks and memory searches.
  • [COMMAND_EXECUTION]: Executes shell commands to interact with session containers and search embedding namespaces.
  • Evidence: Use of the Bash tool to run rvf status and memory search commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — browser-replay