skills/a-canary/arc-skills/pwcheck/Gen Agent Trust Hub

pwcheck

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from external websites which could contain malicious instructions for the agent.
  • Ingestion points: The scripts/pwcheck.mjs script reads the body text of a target website using page.textContent("body") and prints a sample to the console.
  • Boundary markers: The output is not wrapped in clear delimiters (e.g., XML tags or unique string markers) to distinguish the external content from the tool's metadata, nor does it include instructions for the agent to ignore embedded commands.
  • Capability inventory: The skill uses the playwright library to navigate the web and the results are ingested by the agent through stdout.
  • Sanitization: No sanitization or filtering is performed on the extracted body text beyond basic whitespace normalization and string slicing.
  • [EXTERNAL_DOWNLOADS]: The skill's bootstrap instructions involve downloading and installing external dependencies.
  • The SKILL.md file provides instructions to install the playwright package via npm and the Chromium browser binaries via npx playwright install chromium. These are well-known resources maintained by a recognized organization.
  • [COMMAND_EXECUTION]: The skill is designed to execute a Node.js script that performs browser automation.
  • The script uses playwright to interact with web pages, which involves launching a headless browser process and navigating to user-provided URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:47 PM
Security Audit — agent-trust-hub — pwcheck