playwright-skill

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The run.js script executes shell commands via execSync to automate the installation of dependencies and browser binaries.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes a universal executor (run.js) that dynamically wraps and executes arbitrary JavaScript strings provided by the user or agent using Node.js require() on temporary files.
  • [EXTERNAL_DOWNLOADS]: The setup script performs downloads of external packages and browser binaries from the NPM registry and Playwright's distribution servers.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection. Ingestion points: External web content is retrieved via page.goto() in SKILL.md and helper functions like extractTableData in lib/helpers.js. Boundary markers: None are present to distinguish untrusted web data from system instructions. Capability inventory: The skill can perform network operations, write to the local filesystem (e.g., /tmp), and execute arbitrary shell commands via the Playwright and Node.js environment. Sanitization: No validation or sanitization is applied to the content extracted from web pages before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — playwright-skill