playwright-expert

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves interpreting user requirements and website structures to generate automation scripts, which could potentially act upon malicious instructions embedded in those sources. Ingestion points: Identification of requirements and user flows in SKILL.md. Boundary markers: None identified; the instructions do not explicitly tell the agent to ignore instructions embedded in the data it processes. Capability inventory: Full browser automation (Playwright), network request mocking, and the ability to write test and configuration files to the system. Sanitization: No input validation or sanitization routines are specified.
  • [EXTERNAL_DOWNLOADS]: The skill configuration and CI templates reference external resources including GitHub Actions and Playwright browser binaries, which are standard for the tool's operation. Evidence: References to npx playwright install and standard GitHub Actions in references/configuration.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — playwright-expert