playwright-automation

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The install.py script utilizes subprocess.run with shell=True to execute installation commands for the Playwright library and its browser dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill downloads the playwright Python package from the official PyPI registry and the Chromium browser binaries from Microsoft's official distribution infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external websites, creating a surface for indirect prompt injection attacks.
  • Ingestion points: External web content is retrieved using page.content(), page.text_content(), and page.query_selector_all() in SKILL.md and examples/search_example.py.
  • Boundary markers: None. The skill does not define specific delimiters or instructions to the agent for isolating untrusted web content from its own instructions.
  • Capability inventory: The skill has access to Bash, Exec, Read, and Write tools, and demonstrates the ability to execute shell commands via the subprocess module in install.py.
  • Sanitization: None. The provided examples and instructions do not include mechanisms for sanitizing or validating the retrieved web content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:14 PM
Security Audit — agent-trust-hub — playwright-automation