playwright-expert

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from the browser environment, creating a surface for indirect prompt injection.
  • Ingestion points: references/debugging-flaky.md includes instructions for the agent to listen to console and pageerror events from web pages being tested.
  • Boundary markers: The skill does not provide instructions to help the agent differentiate between its core instructions and data captured from external websites.
  • Capability inventory: The agent has the capability to write files (screenshots and traces), intercept network requests via API mocking, and execute shell commands.
  • Sanitization: There is no guidance provided for sanitizing or escaping the content captured from the browser logs before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill contains multiple examples and instructions for executing shell commands for test execution and environment setup.
  • Evidence: Commands such as npx playwright test, npx playwright show-trace, and npm run dev are documented across SKILL.md and references/configuration.md.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of required browser binaries and uses established external workflows for CI/CD integration.
  • Evidence: The configuration in references/configuration.md uses npx playwright install --with-deps and several official GitHub actions including actions/checkout, actions/setup-node, and actions/upload-artifact.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:06 AM
Security Audit — agent-trust-hub — playwright-expert