playwright-interactive
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The instructions explicitly require starting the agent with the
--sandbox danger-full-accessflag. This action removes the security boundaries that normally protect the host system from the agent's actions, allowing unrestricted file and command access. - [COMMAND_EXECUTION]: The skill uses shell-based setup procedures and relies on a
js_repltool to execute code directly in the host environment. - [DYNAMIC_EXECUTION]: The skill makes extensive use of
page.evaluate()andelectronApp.evaluate(). These functions execute arbitrary strings of code within the browser or Electron process, which can be leveraged to interact with internal application states or bypass UI restrictions. - [INDIRECT_PROMPT_INJECTION]: The skill provides capabilities to navigate to and process content from arbitrary URLs via
page.goto(TARGET_URL). Malicious content on these pages could serve as an indirect injection vector if the agent processes the retrieved text or DOM structure. - Ingestion Points: Untrusted data enters the agent context via
page.goto()and subsequent DOM/page inspection inSKILL.md(lines 142, 160, 182). - Boundary Markers: There are no documented boundary markers or instructions to treat page content as untrusted data.
- Capability Inventory: The skill operates with full host access (due to the requested sandbox bypass), utilizes a persistent JavaScript REPL, and has the ability to read/write files and make network requests via Playwright.
- Sanitization: No sanitization logic for data retrieved from automated sessions is present in the provided scripts.
Recommendations
- AI detected serious security threats
Audit Metadata