playwright-expert
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves interpreting user requirements and website structures to generate automation scripts, which could potentially act upon malicious instructions embedded in those sources. Ingestion points: Identification of requirements and user flows in SKILL.md. Boundary markers: None identified; the instructions do not explicitly tell the agent to ignore instructions embedded in the data it processes. Capability inventory: Full browser automation (Playwright), network request mocking, and the ability to write test and configuration files to the system. Sanitization: No input validation or sanitization routines are specified.
- [EXTERNAL_DOWNLOADS]: The skill configuration and CI templates reference external resources including GitHub Actions and Playwright browser binaries, which are standard for the tool's operation. Evidence: References to npx playwright install and standard GitHub Actions in references/configuration.md.
Audit Metadata