skills/ruvnet/ruflo/browser-test/Gen Agent Trust Hub

browser-test

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Web content is ingested via tools such as browser_get-text, browser_get-value, browser_get-title, browser_get-url, and browser_eval as described in SKILL.md.
  • Boundary markers: The instructions recommend using aidefence_is_safe to validate content, which acts as a partial boundary, though it does not eliminate the risk of sophisticated injections.
  • Capability inventory: The skill has access to sensitive tools including Bash, Write, and various browser_* interaction tools specified in the frontmatter.
  • Sanitization: The skill explicitly instructs the agent to pass validation outputs through the aidefence_is_safe tool and to redact strings returned from browser_eval before logging.
  • [DYNAMIC_EXECUTION]: The skill utilizes dynamic JavaScript execution within the browser environment.
  • Evidence: The instructions in SKILL.md suggest using browser_eval for custom JavaScript assertions.
  • Mitigation: The skill includes a instruction to redact and sanitize returned strings via the aidefence_is_safe gate.
  • [COMMAND_EXECUTION]: The skill environment is configured with shell access.
  • Evidence: The YAML frontmatter includes Bash in the allowed-tools list, providing the agent with the capability to execute system commands if prompted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — browser-test