ruvnet/ruflo/tree/main/plugins/ruflo-browser
ruflo-browser
세션을 skill로 사용하는 브라우저 자동화입니다. Playwright + RVF 인지 컨테이너 + ruvector 궤적 + AgentDB 선택기 메모리 + AIDefence PII/주입 게이트를 제공합니다. mod(ADR-445 패턴)로서 강화 전용 도구 가드, 로컬 슬래시 명령, 콘솔이 표시하는 상태 파일을 둡니다.
이 mod 소개
ruflo-browser
세션을 skill로 사용하는 브라우저 자동화입니다. 23개의 mcp__plugin_ruflo-core_ruflo__browser_* 도구를 Playwright로 구동하며, 각 세션을 manifest, 궤적, 스크린샷, 정제된 cookies, 발견 결과를 담은 일급 RVF 인지 컨테이너로 저장합니다. AgentDB에 색인하고 AIDefence로 게이트합니다.
v0.2.0 아키텍처 — 이제 모든 브라우저 세션이 주소 지정 가능하고 재생 가능하며 연합 가능한 아티팩트입니다. 상태는 ADR-0001에 따른 Proposed이며, 핵심 재생 가정에는 Accept 전 spike가 필요합니다(ADR Verification §4 참조).
기반 정렬(ADR-122). 이 플러그인은 사용자에게 보이는 skill 계층입니다. 서명된 궤적(Ed25519 + RVF), 인과 그래프 자가 복구, AIDefence가 인증한 cookie vault, federated MCTS, Session Capsules, Workflow Compiler 등의 기반 프리미티브는
@claude-flow/[email protected]npm 패키지에 포함됩니다. 기반 공지와 추적 issue #2041도 참조하세요.
설치
/plugin marketplace add ruvnet/ruflo
/plugin install ruflo-browser@ruflo
세션 작동 방식
브라우저 세션은 시작할 때 RVF 컨테이너를 할당하고 종료할 때 커밋합니다.
<rvf-id>/
├── manifest.yaml # URL, viewport, profile, runner, lineage
├── trajectory.ndjson # one line per action via ruvector hooks trajectory-step
├── screenshots/<step>.png
├── snapshots/<step>.json # accessibility trees indexed by navigation
├── dom/ # optional, when --with-dom
├── cookies.json # AIDefence-sanitized
└── findings.md # test verdicts, scrape outputs, injection quarantine
rvf ingest <id>로 다시 열고, rvf derive로 포크하며, rvf export로 연합합니다.
명령
/ruflo-browser는 동사 디스패처입니다.
/ruflo-browser ls [--query <text>] # list sessions, AgentDB-indexed
/ruflo-browser show <session-id> # manifest + trajectory + verdict
/ruflo-browser replay <session-id> # re-drive trajectory
/ruflo-browser export <session-id> # rvf export → tar.zst
/ruflo-browser fork <session-id> # rvf derive → new lineage-tracked session
/ruflo-browser purge <session-id> # destroy, keep redacted manifest
/ruflo-browser doctor # check Playwright, MCP, AgentDB, AIDefence
Skills
| Skill | 목적 |
|-------|---------|
| browser-record | 이름을 붙인 추적 세션을 RVF 컨테이너로 엽니다. 다른 프리미티브가 이를 조합합니다. |
| browser-replay | 저장된 궤적을 재생하며, 다른 URL이나 변경된 입력을 선택할 수 있습니다. |
| browser-extract | 저장된 browser-templates 레시피 또는 일회성 추출을 실행합니다. PII를 검사합니다. |
| browser-login | 인증 흐름을 한 번 수행하고 cookies를 정제해 재사용할 수 있도록 vault에 보관합니다. |
| browser-form-fill | 필드 이름 → 값 매핑으로 폼과 상호작용합니다. |
| browser-screenshot-diff | 두 세션 스크린샷의 픽셀 + DOM 차이를 비교합니다(시각적 회귀). |
| browser-auth-flow | 인증 흐름에서 리디렉션 유출, CSRF 누락, 약한 세션 cookie를 조사합니다. |
| browser-test | UI 테스트 레시피이며 browser-record + browser-replay를 조합합니다. |
browser-scrape는 browser-extract로 위임하는 사용 중단 shim이며 v0.3.0에서 제거됩니다.
메모리 계층(AgentDB)
| 네임스페이스 | 키 | 값 | 목적 |
|-----------|-----|-------|---------|
| browser-sessions | <rvf-id> | manifest 요약 + verdict + tags | /ruflo-browser ls용 세션 색인 |
| browser-selectors | <host>:<intent> | {selector, ref, snapshot-hash, last-success} | 임베딩 유사도로 DOM 변경을 견딤 |
| browser-templates | <template-name> | selector chain + post-process를 포함한 스크랩 레시피 | 임시 메모리 문자열을 대체 |
| browser-cookies | <host> | claims로 게이트된 cookie blob + expiry + AIDefence verdict | 재인증 없이 cookie 재사용 |
래핑되지 않은 raw cookies와 tokens는 AgentDB에 들어가지 않습니다. ADR §3을 참조하세요.
AIDefence 게이트(필수)
- 저장 전 스캔 — 스크랩한 모든 문자열은 AgentDB에 저장하기 전에
aidefence_has_pii를 통과합니다. - Cookie 정제 —
aidefence_scan이 엔트로피가 높은 문자열을 표시하고browser-cookies에 vault합니다. - 프롬프트 주입 검사 — LLM으로 돌아가는 추출 텍스트는
aidefence_is_safe를 통과합니다. 발견된 내용은findings.md로 격리됩니다.[email protected](ADR-118)에서는 표준ignore all previous instructions계열에 더해 역할 탈취(you are now …/act as …/pretend to be …)와 jailbreak 표식(DAN mode/developer mode/god mode/root mode)도 잡습니다. 브라우저로 스크랩한 페이지에 효과가 큰 업그레이드입니다.
MCP 표면
기존 18개의 mcp__plugin_ruflo-core_ruflo__browser_* 상호작용 프리미티브(browser-tools.ts의 open/close/click/type/fill/select/check/uncheck/hover/press/scroll/screenshot/snapshot/eval/wait/reload/back/forward)에 v0.2.0에서 구현된 새 browser_session_* 수명 주기 도구 5개를 더해 총 23개입니다.
| 도구 | 목적 |
|------|---------|
| browser_session_record | RVF를 할당하고 ruvector trajectory-begin 및 agent-browser open을 실행합니다. 세션 id와 rvf 경로를 반환합니다. |
| browser_session_end | verdict와 함께 trajectory-end 및 rvf compact를 실행하고 browser-sessions에 AgentDB 색인을 만듭니다. |
| browser_session_replay | 자식 RVF 컨테이너를 파생하고 호출자 수준의 디스패치를 위해 궤적 단계를 로드합니다. |
| browser_template_apply | browser-templates AgentDB 네임스페이스에서 레시피를 가져옵니다. |
| browser_cookie_use | browser-cookies에서 불투명한 vault 핸들을 가져옵니다. raw 값은 반환하지 않습니다. |
구현은 v3/@claude-flow/cli/src/mcp-tools/browser-session-tools.ts에 있으며 mcp-client.ts에 등록됩니다. 각 handler는 고정된 [email protected] CLI를 호출해 궤적과 RVF를 처리하고, 기존 agent-browser CLI로 브라우저 동작을 수행하며, 브리지된 claude-flow memory로 AgentDB를 처리합니다. 의존성이 없으면 충돌하지 않고 구조화된 success: false 오류로 저하됩니다.
browser_session_replay는 의도적으로 프리미티브입니다. 자식 RVF 컨테이너를 파생하고 원본 궤적을 호출자에게 노출하면 호출자가 적절한 browser_* 도구를 통해 각 단계를 디스패치합니다. 이렇게 하면 재생 엔진을 MCP 계층 밖에 두고 핵심 가정(DOM 변경을 가로지르는 재생 충실도)을 도구 내부에 묻지 않아 아래 spike harness로 테스트할 수 있습니다.
검증
서로 보완하는 검사는 2가지입니다.
구조 smoke(빠른 오프라인 검사)
bash plugins/ruflo-browser/scripts/smoke.sh
# Expected on green: "13 passed, 0 failed"
파일 목록, frontmatter 유효성, ADR 상호 참조, agent의 AgentDB 네임스페이스 적용 범위, skills의 allowed-tools 열거, CLI 소스에 수명 주기 MCP 도구 5개가 존재하는지를 확인합니다.
재생 spike(대화형 온라인 검사, Accept 전 게이트)
bash plugins/ruflo-browser/scripts/replay-spike.sh
scripts/SITES.txt의 각 URL에서 기준 세션을 기록하고 재생합니다(기본 10개 사이트, 서로 다른 drift 프로필). 사이트별 verdict와 집계 재생률을 spike-results/<timestamp>/STATUS.md에 기록합니다. ADR 임계값은 **≥80%**이며 이를 충족해야 ADR-0001을 Proposed에서 Accepted로 바꾸는 게이트를 통과합니다. 임계값 미만이면 제안은 “세션을 감사 로그로 사용”하는 수준으로 낮아지고 재생과 screenshot-diff는 best-effort가 됩니다.
spike에는 agent-browser(또는 npx --yes agent-browser), [email protected](npx로 자동 가져옴)와 네트워크 액세스가 필요합니다. smoke test의 일부가 아니며 실행은 의도적인 감사 단계입니다.
아키텍처 결정
관련 플러그인
ruflo-ruvector— 궤적 hooks, SONA 패턴 증류, MCP 도구ruflo-agentdb—browser-sessions,browser-selectors,browser-templates,browser-cookies를 뒷받침하는 컨트롤러ruflo-aidefence— PII / 프롬프트 주입 게이트ruflo-federation— RVF export로 설치 간 세션 공유
라이선스
MIT
mod로 사용
모델 호출, 네트워크, 프로세스가 필요 없는 function hooks(ADR-445 패턴)입니다.
- 도구 가드(기본 on, 강화만 가능: 거부만 가능). file/javascript/data/chrome URL로 향하는 browser_open, 포함된 자격 증명이나 클라우드 메타데이터 호스트를 가진 URL, 페이지 격리를 없애거나 디버그 포트를 여는 Chrome 실행 플래그를 거부합니다. cookies/storage를 읽는 browser_eval 스크립트와 페이지 밖으로 이를 보낼 수 있는 스크립트도 거부합니다. 거부할 때 문제의 값은 절대 다시 표시하지 않습니다.
- **
/browser-mod**는 로컬에서status,scan <js>,url <url>(가드가 거부할지 여부)에 답합니다. 플러그인 자체의 명령 및 skills와 구분되는 이름이며, hook은 후자를 답할 수 없습니다. - 상태 파일
.claude-flow/browser-mod/status.json(version,updatedMs,checked,blocked,byRule)은 세션 시작과 각 거부 뒤에 기록되고 콘솔이 읽습니다.
옵션(userConfig)은 guard(on/off, 기본 on)와 strictUrls(기본 off: localhost 바깥의 일반 http도 거부)입니다.
테스트: claude plugin validate plugins/ruflo-browser && claude plugin test plugins/ruflo-browser && bash plugins/ruflo-browser/scripts/smoke.sh.
설치
먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.
claude plugin marketplace add ruvnet/ruflo claude plugin install ruflo-browser
원문 / README
ruflo-browser
Session-as-skill browser automation. Playwright-backed via 23 mcp__plugin_ruflo-core_ruflo__browser_* tools, with each session captured as a first-class RVF cognitive container holding manifest + trajectory + screenshots + sanitized cookies + findings, indexed in AgentDB and gated by AIDefence.
v0.2.0 architecture — every browser session is now an addressable, replayable, federatable artifact. Status is Proposed per ADR-0001; the load-bearing replay assumption requires a pre-Accept spike (see ADR Verification §4).
Substrate alignment (ADR-122). This plugin is the user-facing skill layer; the substrate primitives — signed trajectories (Ed25519 + RVF), causal-graph self-healing, AIDefence-attested cookie vault, federated MCTS, Session Capsules, Workflow Compiler — ship in the
@claude-flow/[email protected]npm package. See the substrate announcement and tracking issue #2041.
Install
/plugin marketplace add ruvnet/ruflo
/plugin install ruflo-browser@ruflo
How sessions work
A browser session is allocated an RVF container at session-start and committed at session-end:
<rvf-id>/
├── manifest.yaml # URL, viewport, profile, runner, lineage
├── trajectory.ndjson # one line per action via ruvector hooks trajectory-step
├── screenshots/<step>.png
├── snapshots/<step>.json # accessibility trees indexed by navigation
├── dom/ # optional, when --with-dom
├── cookies.json # AIDefence-sanitized
└── findings.md # test verdicts, scrape outputs, injection quarantine
Re-open with rvf ingest <id>, fork with rvf derive, federate with rvf export.
Commands
/ruflo-browser is a verb dispatcher:
/ruflo-browser ls [--query <text>] # list sessions, AgentDB-indexed
/ruflo-browser show <session-id> # manifest + trajectory + verdict
/ruflo-browser replay <session-id> # re-drive trajectory
/ruflo-browser export <session-id> # rvf export → tar.zst
/ruflo-browser fork <session-id> # rvf derive → new lineage-tracked session
/ruflo-browser purge <session-id> # destroy, keep redacted manifest
/ruflo-browser doctor # check Playwright, MCP, AgentDB, AIDefence
Skills
| Skill | Purpose |
|-------|---------|
| browser-record | Open a named, traced session into an RVF container. Primitive others compose. |
| browser-replay | Replay a stored trajectory, optionally on a different URL or with mutated inputs. |
| browser-extract | Run a stored browser-templates recipe or one-shot extraction. PII-scanned. |
| browser-login | Drive an auth flow once, sanitize+vault cookies for reuse. |
| browser-form-fill | Form interaction with field-name → value mapping. |
| browser-screenshot-diff | Pixel + DOM diff between two session screenshots (visual regression). |
| browser-auth-flow | Probe an auth flow for redirect leaks, missing CSRF, weak session cookies. |
| browser-test | UI test recipe — composes browser-record + browser-replay. |
browser-scrape is a deprecation shim that delegates to browser-extract. Removed in v0.3.0.
Memory layer (AgentDB)
| Namespace | Key | Value | Purpose |
|-----------|-----|-------|---------|
| browser-sessions | <rvf-id> | manifest summary + verdict + tags | session index for /ruflo-browser ls |
| browser-selectors | <host>:<intent> | {selector, ref, snapshot-hash, last-success} | survives DOM drift via embedding similarity |
| browser-templates | <template-name> | scrape recipe with selector chain + post-process | replaces ad-hoc memory strings |
| browser-cookies | <host> | claims-gated cookie blob + expiry + AIDefence verdict | cookie reuse without re-auth |
Raw cookies and tokens never enter AgentDB unwrapped — see ADR §3.
AIDefence gates (mandatory)
- Pre-storage scan — every scraped string passes
aidefence_has_piibefore AgentDB store. - Cookie sanitization —
aidefence_scanflags high-entropy strings; vault them inbrowser-cookies. - Prompt-injection check — extracted text returning to an LLM passes
aidefence_is_safe. Hits get quarantined tofindings.md. With[email protected](ADR-118) the check now catches role-hijack (you are now …/act as …/pretend to be …) and jailbreak markers (DAN mode/developer mode/god mode/root mode) in addition to the canonicalignore all previous instructionsfamily — high-leverage upgrade for browser-scraped pages.
MCP surface
18 existing mcp__plugin_ruflo-core_ruflo__browser_* interaction primitives (in browser-tools.ts: open/close/click/type/fill/select/check/uncheck/hover/press/scroll/screenshot/snapshot/eval/wait/reload/back/forward) + 5 new browser_session_* lifecycle tools (implemented in v0.2.0) for a total of 23:
| Tool | Purpose |
|------|---------|
| browser_session_record | RVF allocate + ruvector trajectory-begin + agent-browser open. Returns session id + rvf path. |
| browser_session_end | trajectory-end with verdict + rvf compact + AgentDB index in browser-sessions. |
| browser_session_replay | RVF derive child container + load trajectory steps for caller-level dispatch. |
| browser_template_apply | Fetch a recipe from browser-templates AgentDB namespace. |
| browser_cookie_use | Fetch an opaque vault handle from browser-cookies; raw values never returned. |
Implementation: v3/@claude-flow/cli/src/mcp-tools/browser-session-tools.ts, registered in mcp-client.ts. Each handler shells out to the pinned [email protected] CLI for trajectory + RVF, the existing agent-browser CLI for browser actions, and the bridged claude-flow memory for AgentDB. Missing dependencies degrade with structured success: false errors instead of crashing.
browser_session_replay is deliberately a primitive: it derives a child RVF container and surfaces the source trajectory so the caller dispatches each step through the appropriate browser_* tool. That keeps the replay engine out of the MCP layer and makes the load-bearing assumption (replay-fidelity across DOM drift) testable via the spike harness below rather than buried in tool internals.
Verification
Two complementary checks:
Structural smoke (fast, offline)
bash plugins/ruflo-browser/scripts/smoke.sh
# Expected on green: "13 passed, 0 failed"
Verifies plugin structural soundness — file inventory, frontmatter validity, ADR cross-references, AgentDB namespace coverage in the agent, allowed-tools enumeration in skills, and that the 5 lifecycle MCP tools are present in the CLI source.
Replay spike (interactive, online — pre-Accept gate)
bash plugins/ruflo-browser/scripts/replay-spike.sh
Records + replays a baseline session against each URL in scripts/SITES.txt (10 sites by default, varying drift profiles). Writes spike-results/<timestamp>/STATUS.md with per-site verdicts and the aggregate replay rate. The ADR threshold is ≥80%; meeting it is the gate to flip ADR-0001 from Proposed → Accepted. Below the threshold, the proposal degrades to "session as audit log" (replay and screenshot-diff become best-effort).
The spike requires agent-browser (or npx --yes agent-browser), [email protected] (auto-fetched via npx), and network access. It is not part of the smoke test — running it is a deliberate audit step.
Architecture Decisions
Related Plugins
ruflo-ruvector— trajectory hooks, SONA pattern distillation, MCP toolsruflo-agentdb— controllers backingbrowser-sessions,browser-selectors,browser-templates,browser-cookiesruflo-aidefence— PII / prompt-injection gatesruflo-federation— cross-installation session sharing via RVF export
License
MIT
As a mod
Function hooks (ADR-445 pattern, hooks/register.ts) that need no model call, no network and no process:
- Tool guard (default on, tighten-only: it can only deny). Refuses browser_open to file/javascript/data/chrome URLs, URLs with embedded credentials or cloud-metadata hosts, and Chrome launch flags that drop page isolation or open a debug port; refuses browser_eval scripts that read cookies/storage and can also send them off the page. A refusal never echoes the offending value.
/browser-modanswers locally:status,scan <js>andurl <url>(would the guard refuse this?). (A distinct name from the plugin's own commands/skills, which no hook can answer.)- Status file
.claude-flow/browser-mod/status.json(version,updatedMs,checked,blocked,byRule) is written at session start and after each refusal; the console reads it.
Options (userConfig): guard (on/off, default on), strictUrls (default off: also refuse plain http outside localhost).
Test: claude plugin validate plugins/ruflo-browser && claude plugin test plugins/ruflo-browser && bash plugins/ruflo-browser/scripts/smoke.sh.