playwright-expert
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from the browser environment, creating a surface for indirect prompt injection.
- Ingestion points:
references/debugging-flaky.mdincludes instructions for the agent to listen toconsoleandpageerrorevents from web pages being tested. - Boundary markers: The skill does not provide instructions to help the agent differentiate between its core instructions and data captured from external websites.
- Capability inventory: The agent has the capability to write files (screenshots and traces), intercept network requests via API mocking, and execute shell commands.
- Sanitization: There is no guidance provided for sanitizing or escaping the content captured from the browser logs before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill contains multiple examples and instructions for executing shell commands for test execution and environment setup.
- Evidence: Commands such as
npx playwright test,npx playwright show-trace, andnpm run devare documented acrossSKILL.mdandreferences/configuration.md. - [EXTERNAL_DOWNLOADS]: The skill references the installation of required browser binaries and uses established external workflows for CI/CD integration.
- Evidence: The configuration in
references/configuration.mdusesnpx playwright install --with-depsand several official GitHub actions includingactions/checkout,actions/setup-node, andactions/upload-artifact.
Audit Metadata