browser-replay
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes session data from external trajectory files to determine its sequence of actions, which could allow malicious instructions in the recorded data to influence the agent's behavior.
- Ingestion points:
Read .../trajectory.ndjson(SKILL.md) - Boundary markers: None present to distinguish recorded data from instructions.
- Capability inventory:
mcp__plugin_ruflo-core_ruflo__browser_eval,Bash, and various browser interaction tools (SKILL.md). - Sanitization: No sanitization or validation of the recorded trajectory content is mentioned.
- [DYNAMIC_EXECUTION]: The skill performs dynamic execution by replaying recorded arguments through browser evaluation tools.
- Evidence: Use of
mcp__plugin_ruflo-core_ruflo__browser_evalwith arguments loaded directly from the trajectory file. - [EXTERNAL_DOWNLOADS]: Fetches and executes CLI tools directly from the NPM registry at runtime.
- Evidence: Usage of
npx -y ruvector@0.2.25andnpx -y @claude-flow/cli@latestto perform status checks and memory searches. - [COMMAND_EXECUTION]: Executes shell commands to interact with session containers and search embedding namespaces.
- Evidence: Use of the
Bashtool to runrvf statusandmemory searchcommands.
Audit Metadata