browser-screenshot-diff
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing local system commands via the Bash tool to query session file metadata.
- Evidence: Uses
npx -y ruvector@0.2.25 rvf statusinside the step instructions. - [EXTERNAL_DOWNLOADS]: The skill specifies fetching an external tool from the Node package registry at runtime.
- Evidence: Directs the execution of
ruvector@0.2.25via npx. - [INDIRECT_PROMPT_INJECTION]: The skill ingests raw session logs and accessibility snapshots which could include arbitrary untrusted textual data from third-party sites visited during the recorded sessions.
- Ingestion points: Processes
trajectory.ndjsonand node-by-node accessibility trees within the session data (SKILL.md). - Boundary markers: No specific delimiters or validation logic are implemented to separate data from instructions during analysis.
- Capability inventory: Has access to
Bash,Read,Write, andmcp__plugin_ruflo-core_ruflo__browser_evaltools which allow local system and browser execution. - Sanitization: There is no documentation or reference to data escaping or pre-validation of structural DOM/text components prior to parsing.
Audit Metadata