playwright-automation
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
install.pyscript utilizessubprocess.runwithshell=Trueto execute installation commands for the Playwright library and its browser dependencies. - [EXTERNAL_DOWNLOADS]: The skill downloads the
playwrightPython package from the official PyPI registry and the Chromium browser binaries from Microsoft's official distribution infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external websites, creating a surface for indirect prompt injection attacks.
- Ingestion points: External web content is retrieved using
page.content(),page.text_content(), andpage.query_selector_all()inSKILL.mdandexamples/search_example.py. - Boundary markers: None. The skill does not define specific delimiters or instructions to the agent for isolating untrusted web content from its own instructions.
- Capability inventory: The skill has access to
Bash,Exec,Read, andWritetools, and demonstrates the ability to execute shell commands via thesubprocessmodule ininstall.py. - Sanitization: None. The provided examples and instructions do not include mechanisms for sanitizing or validating the retrieved web content before it is processed by the agent.
Audit Metadata