pwcheck
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from external websites which could contain malicious instructions for the agent.
- Ingestion points: The
scripts/pwcheck.mjsscript reads the body text of a target website usingpage.textContent("body")and prints a sample to the console. - Boundary markers: The output is not wrapped in clear delimiters (e.g., XML tags or unique string markers) to distinguish the external content from the tool's metadata, nor does it include instructions for the agent to ignore embedded commands.
- Capability inventory: The skill uses the
playwrightlibrary to navigate the web and the results are ingested by the agent through stdout. - Sanitization: No sanitization or filtering is performed on the extracted body text beyond basic whitespace normalization and string slicing.
- [EXTERNAL_DOWNLOADS]: The skill's bootstrap instructions involve downloading and installing external dependencies.
- The
SKILL.mdfile provides instructions to install theplaywrightpackage vianpmand the Chromium browser binaries vianpx playwright install chromium. These are well-known resources maintained by a recognized organization. - [COMMAND_EXECUTION]: The skill is designed to execute a Node.js script that performs browser automation.
- The script uses
playwrightto interact with web pages, which involves launching a headless browser process and navigating to user-provided URLs.
Audit Metadata