playwright-interactive

Fail

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The instructions explicitly require starting the agent with the --sandbox danger-full-access flag. This action removes the security boundaries that normally protect the host system from the agent's actions, allowing unrestricted file and command access.
  • [COMMAND_EXECUTION]: The skill uses shell-based setup procedures and relies on a js_repl tool to execute code directly in the host environment.
  • [DYNAMIC_EXECUTION]: The skill makes extensive use of page.evaluate() and electronApp.evaluate(). These functions execute arbitrary strings of code within the browser or Electron process, which can be leveraged to interact with internal application states or bypass UI restrictions.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides capabilities to navigate to and process content from arbitrary URLs via page.goto(TARGET_URL). Malicious content on these pages could serve as an indirect injection vector if the agent processes the retrieved text or DOM structure.
  • Ingestion Points: Untrusted data enters the agent context via page.goto() and subsequent DOM/page inspection in SKILL.md (lines 142, 160, 182).
  • Boundary Markers: There are no documented boundary markers or instructions to treat page content as untrusted data.
  • Capability Inventory: The skill operates with full host access (due to the requested sandbox bypass), utilizes a persistent JavaScript REPL, and has the ability to read/write files and make network requests via Playwright.
  • Sanitization: No sanitization logic for data retrieved from automated sessions is present in the provided scripts.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 4, 2026, 04:39 PM