skills/5dive-ai/skills/playwright-e2e/Gen Agent Trust Hub

playwright-e2e

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires running shell commands such as npm install, npx playwright test, and node verify.mjs to set up the environment and execute test scripts. These are standard operations for the described workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides capabilities for an agent to visit and interact with potentially untrusted web pages, which can contain malicious instructions intended to manipulate the agent.
  • Ingestion points: The skill uses page.goto() to load URLs and methods like page.getByRole() or p.title() to extract content from the browser DOM in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions to ignore commands found within the external web content.
  • Capability inventory: The skill has the ability to execute shell commands (npx playwright) and write files (page.screenshot()) as shown in SKILL.md.
  • Sanitization: The skill does not implement any validation or sanitization of the content retrieved from the web pages before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:47 PM
Security Audit — agent-trust-hub — playwright-e2e