ClaudeMods
☰
KO
● 0 명 접속 중 · 조회 0 회
후원프로젝트 제출
GitHub 저장소 · 작성자 ruvnet

ruflo-browser

세션을 skill로 사용하는 브라우저 자동화입니다. Playwright + RVF 인지 컨테이너 + ruvector 궤적 + AgentDB 선택기 메모리 + AIDefence PII/주입 게이트를 제공합니다. mod(ADR-445 패턴)로서 강화 전용 도구 가드, 로컬 슬래시 명령, 콘솔이 표시하는 상태 파일을 둡니다.

번역 완료

이 mod 소개

ruflo-browser

세션을 skill로 사용하는 브라우저 자동화입니다. 23개의 mcp__plugin_ruflo-core_ruflo__browser_* 도구를 Playwright로 구동하며, 각 세션을 manifest, 궤적, 스크린샷, 정제된 cookies, 발견 결과를 담은 일급 RVF 인지 컨테이너로 저장합니다. AgentDB에 색인하고 AIDefence로 게이트합니다.

v0.2.0 아키텍처 — 이제 모든 브라우저 세션이 주소 지정 가능하고 재생 가능하며 연합 가능한 아티팩트입니다. 상태는 ADR-0001에 따른 Proposed이며, 핵심 재생 가정에는 Accept 전 spike가 필요합니다(ADR Verification §4 참조).

기반 정렬(ADR-122). 이 플러그인은 사용자에게 보이는 skill 계층입니다. 서명된 궤적(Ed25519 + RVF), 인과 그래프 자가 복구, AIDefence가 인증한 cookie vault, federated MCTS, Session Capsules, Workflow Compiler 등의 기반 프리미티브는 @claude-flow/[email protected] npm 패키지에 포함됩니다. 기반 공지와 추적 issue #2041도 참조하세요.

설치

/plugin marketplace add ruvnet/ruflo
/plugin install ruflo-browser@ruflo

세션 작동 방식

브라우저 세션은 시작할 때 RVF 컨테이너를 할당하고 종료할 때 커밋합니다.

<rvf-id>/
├── manifest.yaml         # URL, viewport, profile, runner, lineage
├── trajectory.ndjson     # one line per action via ruvector hooks trajectory-step
├── screenshots/<step>.png
├── snapshots/<step>.json # accessibility trees indexed by navigation
├── dom/                  # optional, when --with-dom
├── cookies.json          # AIDefence-sanitized
└── findings.md           # test verdicts, scrape outputs, injection quarantine

rvf ingest <id>로 다시 열고, rvf derive로 포크하며, rvf export로 연합합니다.

명령

/ruflo-browser는 동사 디스패처입니다.

/ruflo-browser ls [--query <text>]      # list sessions, AgentDB-indexed
/ruflo-browser show <session-id>        # manifest + trajectory + verdict
/ruflo-browser replay <session-id>      # re-drive trajectory
/ruflo-browser export <session-id>      # rvf export → tar.zst
/ruflo-browser fork <session-id>        # rvf derive → new lineage-tracked session
/ruflo-browser purge <session-id>       # destroy, keep redacted manifest
/ruflo-browser doctor                   # check Playwright, MCP, AgentDB, AIDefence

Skills

| Skill | 목적 | |-------|---------| | browser-record | 이름을 붙인 추적 세션을 RVF 컨테이너로 엽니다. 다른 프리미티브가 이를 조합합니다. | | browser-replay | 저장된 궤적을 재생하며, 다른 URL이나 변경된 입력을 선택할 수 있습니다. | | browser-extract | 저장된 browser-templates 레시피 또는 일회성 추출을 실행합니다. PII를 검사합니다. | | browser-login | 인증 흐름을 한 번 수행하고 cookies를 정제해 재사용할 수 있도록 vault에 보관합니다. | | browser-form-fill | 필드 이름 → 값 매핑으로 폼과 상호작용합니다. | | browser-screenshot-diff | 두 세션 스크린샷의 픽셀 + DOM 차이를 비교합니다(시각적 회귀). | | browser-auth-flow | 인증 흐름에서 리디렉션 유출, CSRF 누락, 약한 세션 cookie를 조사합니다. | | browser-test | UI 테스트 레시피이며 browser-record + browser-replay를 조합합니다. |

browser-scrape는 browser-extract로 위임하는 사용 중단 shim이며 v0.3.0에서 제거됩니다.

메모리 계층(AgentDB)

| 네임스페이스 | 키 | 값 | 목적 | |-----------|-----|-------|---------| | browser-sessions | <rvf-id> | manifest 요약 + verdict + tags | /ruflo-browser ls용 세션 색인 | | browser-selectors | <host>:<intent> | {selector, ref, snapshot-hash, last-success} | 임베딩 유사도로 DOM 변경을 견딤 | | browser-templates | <template-name> | selector chain + post-process를 포함한 스크랩 레시피 | 임시 메모리 문자열을 대체 | | browser-cookies | <host> | claims로 게이트된 cookie blob + expiry + AIDefence verdict | 재인증 없이 cookie 재사용 |

래핑되지 않은 raw cookies와 tokens는 AgentDB에 들어가지 않습니다. ADR §3을 참조하세요.

AIDefence 게이트(필수)

  1. 저장 전 스캔 — 스크랩한 모든 문자열은 AgentDB에 저장하기 전에 aidefence_has_pii를 통과합니다.
  2. Cookie 정제 — aidefence_scan이 엔트로피가 높은 문자열을 표시하고 browser-cookies에 vault합니다.
  3. 프롬프트 주입 검사 — LLM으로 돌아가는 추출 텍스트는 aidefence_is_safe를 통과합니다. 발견된 내용은 findings.md로 격리됩니다. [email protected](ADR-118)에서는 표준 ignore all previous instructions 계열에 더해 역할 탈취(you are now … / act as … / pretend to be …)와 jailbreak 표식(DAN mode / developer mode / god mode / root mode)도 잡습니다. 브라우저로 스크랩한 페이지에 효과가 큰 업그레이드입니다.

MCP 표면

기존 18개의 mcp__plugin_ruflo-core_ruflo__browser_* 상호작용 프리미티브(browser-tools.ts의 open/close/click/type/fill/select/check/uncheck/hover/press/scroll/screenshot/snapshot/eval/wait/reload/back/forward)에 v0.2.0에서 구현된 새 browser_session_* 수명 주기 도구 5개를 더해 총 23개입니다.

| 도구 | 목적 | |------|---------| | browser_session_record | RVF를 할당하고 ruvector trajectory-begin 및 agent-browser open을 실행합니다. 세션 id와 rvf 경로를 반환합니다. | | browser_session_end | verdict와 함께 trajectory-end 및 rvf compact를 실행하고 browser-sessions에 AgentDB 색인을 만듭니다. | | browser_session_replay | 자식 RVF 컨테이너를 파생하고 호출자 수준의 디스패치를 위해 궤적 단계를 로드합니다. | | browser_template_apply | browser-templates AgentDB 네임스페이스에서 레시피를 가져옵니다. | | browser_cookie_use | browser-cookies에서 불투명한 vault 핸들을 가져옵니다. raw 값은 반환하지 않습니다. |

구현은 v3/@claude-flow/cli/src/mcp-tools/browser-session-tools.ts에 있으며 mcp-client.ts에 등록됩니다. 각 handler는 고정된 [email protected] CLI를 호출해 궤적과 RVF를 처리하고, 기존 agent-browser CLI로 브라우저 동작을 수행하며, 브리지된 claude-flow memory로 AgentDB를 처리합니다. 의존성이 없으면 충돌하지 않고 구조화된 success: false 오류로 저하됩니다.

browser_session_replay는 의도적으로 프리미티브입니다. 자식 RVF 컨테이너를 파생하고 원본 궤적을 호출자에게 노출하면 호출자가 적절한 browser_* 도구를 통해 각 단계를 디스패치합니다. 이렇게 하면 재생 엔진을 MCP 계층 밖에 두고 핵심 가정(DOM 변경을 가로지르는 재생 충실도)을 도구 내부에 묻지 않아 아래 spike harness로 테스트할 수 있습니다.

검증

서로 보완하는 검사는 2가지입니다.

구조 smoke(빠른 오프라인 검사)

bash plugins/ruflo-browser/scripts/smoke.sh
# Expected on green: "13 passed, 0 failed"

파일 목록, frontmatter 유효성, ADR 상호 참조, agent의 AgentDB 네임스페이스 적용 범위, skills의 allowed-tools 열거, CLI 소스에 수명 주기 MCP 도구 5개가 존재하는지를 확인합니다.

재생 spike(대화형 온라인 검사, Accept 전 게이트)

bash plugins/ruflo-browser/scripts/replay-spike.sh

scripts/SITES.txt의 각 URL에서 기준 세션을 기록하고 재생합니다(기본 10개 사이트, 서로 다른 drift 프로필). 사이트별 verdict와 집계 재생률을 spike-results/<timestamp>/STATUS.md에 기록합니다. ADR 임계값은 **≥80%**이며 이를 충족해야 ADR-0001을 Proposed에서 Accepted로 바꾸는 게이트를 통과합니다. 임계값 미만이면 제안은 “세션을 감사 로그로 사용”하는 수준으로 낮아지고 재생과 screenshot-diff는 best-effort가 됩니다.

spike에는 agent-browser(또는 npx --yes agent-browser), [email protected](npx로 자동 가져옴)와 네트워크 액세스가 필요합니다. smoke test의 일부가 아니며 실행은 의도적인 감사 단계입니다.

아키텍처 결정

관련 플러그인

  • ruflo-ruvector — 궤적 hooks, SONA 패턴 증류, MCP 도구
  • ruflo-agentdb — browser-sessions, browser-selectors, browser-templates, browser-cookies를 뒷받침하는 컨트롤러
  • ruflo-aidefence — PII / 프롬프트 주입 게이트
  • ruflo-federation — RVF export로 설치 간 세션 공유

라이선스

MIT

mod로 사용

모델 호출, 네트워크, 프로세스가 필요 없는 function hooks(ADR-445 패턴)입니다.

  • 도구 가드(기본 on, 강화만 가능: 거부만 가능). file/javascript/data/chrome URL로 향하는 browser_open, 포함된 자격 증명이나 클라우드 메타데이터 호스트를 가진 URL, 페이지 격리를 없애거나 디버그 포트를 여는 Chrome 실행 플래그를 거부합니다. cookies/storage를 읽는 browser_eval 스크립트와 페이지 밖으로 이를 보낼 수 있는 스크립트도 거부합니다. 거부할 때 문제의 값은 절대 다시 표시하지 않습니다.
  • **/browser-mod**는 로컬에서 status, scan <js>, url <url>(가드가 거부할지 여부)에 답합니다. 플러그인 자체의 명령 및 skills와 구분되는 이름이며, hook은 후자를 답할 수 없습니다.
  • 상태 파일 .claude-flow/browser-mod/status.json(version, updatedMs, checked, blocked, byRule)은 세션 시작과 각 거부 뒤에 기록되고 콘솔이 읽습니다.

옵션(userConfig)은 guard(on/off, 기본 on)와 strictUrls(기본 off: localhost 바깥의 일반 http도 거부)입니다.

테스트: claude plugin validate plugins/ruflo-browser && claude plugin test plugins/ruflo-browser && bash plugins/ruflo-browser/scripts/smoke.sh.

설치

먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.

claude plugin marketplace add ruvnet/ruflo
claude plugin install ruflo-browser
원문 / README

ruflo-browser

Session-as-skill browser automation. Playwright-backed via 23 mcp__plugin_ruflo-core_ruflo__browser_* tools, with each session captured as a first-class RVF cognitive container holding manifest + trajectory + screenshots + sanitized cookies + findings, indexed in AgentDB and gated by AIDefence.

v0.2.0 architecture — every browser session is now an addressable, replayable, federatable artifact. Status is Proposed per ADR-0001; the load-bearing replay assumption requires a pre-Accept spike (see ADR Verification §4).

Substrate alignment (ADR-122). This plugin is the user-facing skill layer; the substrate primitives — signed trajectories (Ed25519 + RVF), causal-graph self-healing, AIDefence-attested cookie vault, federated MCTS, Session Capsules, Workflow Compiler — ship in the @claude-flow/[email protected] npm package. See the substrate announcement and tracking issue #2041.

Install

/plugin marketplace add ruvnet/ruflo
/plugin install ruflo-browser@ruflo

How sessions work

A browser session is allocated an RVF container at session-start and committed at session-end:

<rvf-id>/
├── manifest.yaml         # URL, viewport, profile, runner, lineage
├── trajectory.ndjson     # one line per action via ruvector hooks trajectory-step
├── screenshots/<step>.png
├── snapshots/<step>.json # accessibility trees indexed by navigation
├── dom/                  # optional, when --with-dom
├── cookies.json          # AIDefence-sanitized
└── findings.md           # test verdicts, scrape outputs, injection quarantine

Re-open with rvf ingest <id>, fork with rvf derive, federate with rvf export.

Commands

/ruflo-browser is a verb dispatcher:

/ruflo-browser ls [--query <text>]      # list sessions, AgentDB-indexed
/ruflo-browser show <session-id>        # manifest + trajectory + verdict
/ruflo-browser replay <session-id>      # re-drive trajectory
/ruflo-browser export <session-id>      # rvf export → tar.zst
/ruflo-browser fork <session-id>        # rvf derive → new lineage-tracked session
/ruflo-browser purge <session-id>       # destroy, keep redacted manifest
/ruflo-browser doctor                   # check Playwright, MCP, AgentDB, AIDefence

Skills

| Skill | Purpose | |-------|---------| | browser-record | Open a named, traced session into an RVF container. Primitive others compose. | | browser-replay | Replay a stored trajectory, optionally on a different URL or with mutated inputs. | | browser-extract | Run a stored browser-templates recipe or one-shot extraction. PII-scanned. | | browser-login | Drive an auth flow once, sanitize+vault cookies for reuse. | | browser-form-fill | Form interaction with field-name → value mapping. | | browser-screenshot-diff | Pixel + DOM diff between two session screenshots (visual regression). | | browser-auth-flow | Probe an auth flow for redirect leaks, missing CSRF, weak session cookies. | | browser-test | UI test recipe — composes browser-record + browser-replay. |

browser-scrape is a deprecation shim that delegates to browser-extract. Removed in v0.3.0.

Memory layer (AgentDB)

| Namespace | Key | Value | Purpose | |-----------|-----|-------|---------| | browser-sessions | <rvf-id> | manifest summary + verdict + tags | session index for /ruflo-browser ls | | browser-selectors | <host>:<intent> | {selector, ref, snapshot-hash, last-success} | survives DOM drift via embedding similarity | | browser-templates | <template-name> | scrape recipe with selector chain + post-process | replaces ad-hoc memory strings | | browser-cookies | <host> | claims-gated cookie blob + expiry + AIDefence verdict | cookie reuse without re-auth |

Raw cookies and tokens never enter AgentDB unwrapped — see ADR §3.

AIDefence gates (mandatory)

  1. Pre-storage scan — every scraped string passes aidefence_has_pii before AgentDB store.
  2. Cookie sanitization — aidefence_scan flags high-entropy strings; vault them in browser-cookies.
  3. Prompt-injection check — extracted text returning to an LLM passes aidefence_is_safe. Hits get quarantined to findings.md. With [email protected] (ADR-118) the check now catches role-hijack (you are now … / act as … / pretend to be …) and jailbreak markers (DAN mode / developer mode / god mode / root mode) in addition to the canonical ignore all previous instructions family — high-leverage upgrade for browser-scraped pages.

MCP surface

18 existing mcp__plugin_ruflo-core_ruflo__browser_* interaction primitives (in browser-tools.ts: open/close/click/type/fill/select/check/uncheck/hover/press/scroll/screenshot/snapshot/eval/wait/reload/back/forward) + 5 new browser_session_* lifecycle tools (implemented in v0.2.0) for a total of 23:

| Tool | Purpose | |------|---------| | browser_session_record | RVF allocate + ruvector trajectory-begin + agent-browser open. Returns session id + rvf path. | | browser_session_end | trajectory-end with verdict + rvf compact + AgentDB index in browser-sessions. | | browser_session_replay | RVF derive child container + load trajectory steps for caller-level dispatch. | | browser_template_apply | Fetch a recipe from browser-templates AgentDB namespace. | | browser_cookie_use | Fetch an opaque vault handle from browser-cookies; raw values never returned. |

Implementation: v3/@claude-flow/cli/src/mcp-tools/browser-session-tools.ts, registered in mcp-client.ts. Each handler shells out to the pinned [email protected] CLI for trajectory + RVF, the existing agent-browser CLI for browser actions, and the bridged claude-flow memory for AgentDB. Missing dependencies degrade with structured success: false errors instead of crashing.

browser_session_replay is deliberately a primitive: it derives a child RVF container and surfaces the source trajectory so the caller dispatches each step through the appropriate browser_* tool. That keeps the replay engine out of the MCP layer and makes the load-bearing assumption (replay-fidelity across DOM drift) testable via the spike harness below rather than buried in tool internals.

Verification

Two complementary checks:

Structural smoke (fast, offline)

bash plugins/ruflo-browser/scripts/smoke.sh
# Expected on green: "13 passed, 0 failed"

Verifies plugin structural soundness — file inventory, frontmatter validity, ADR cross-references, AgentDB namespace coverage in the agent, allowed-tools enumeration in skills, and that the 5 lifecycle MCP tools are present in the CLI source.

Replay spike (interactive, online — pre-Accept gate)

bash plugins/ruflo-browser/scripts/replay-spike.sh

Records + replays a baseline session against each URL in scripts/SITES.txt (10 sites by default, varying drift profiles). Writes spike-results/<timestamp>/STATUS.md with per-site verdicts and the aggregate replay rate. The ADR threshold is ≥80%; meeting it is the gate to flip ADR-0001 from Proposed → Accepted. Below the threshold, the proposal degrades to "session as audit log" (replay and screenshot-diff become best-effort).

The spike requires agent-browser (or npx --yes agent-browser), [email protected] (auto-fetched via npx), and network access. It is not part of the smoke test — running it is a deliberate audit step.

Architecture Decisions

Related Plugins

  • ruflo-ruvector — trajectory hooks, SONA pattern distillation, MCP tools
  • ruflo-agentdb — controllers backing browser-sessions, browser-selectors, browser-templates, browser-cookies
  • ruflo-aidefence — PII / prompt-injection gates
  • ruflo-federation — cross-installation session sharing via RVF export

License

MIT

As a mod

Function hooks (ADR-445 pattern, hooks/register.ts) that need no model call, no network and no process:

  • Tool guard (default on, tighten-only: it can only deny). Refuses browser_open to file/javascript/data/chrome URLs, URLs with embedded credentials or cloud-metadata hosts, and Chrome launch flags that drop page isolation or open a debug port; refuses browser_eval scripts that read cookies/storage and can also send them off the page. A refusal never echoes the offending value.
  • /browser-mod answers locally: status, scan <js> and url <url> (would the guard refuse this?). (A distinct name from the plugin's own commands/skills, which no hook can answer.)
  • Status file .claude-flow/browser-mod/status.json (version, updatedMs, checked, blocked, byRule) is written at session start and after each refusal; the console reads it.

Options (userConfig): guard (on/off, default on), strictUrls (default off: also refuse plain http outside localhost).

Test: claude plugin validate plugins/ruflo-browser && claude plugin test plugins/ruflo-browser && bash plugins/ruflo-browser/scripts/smoke.sh.

비슷한 프로젝트