webapp-testing

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The helper utility script scripts/playwright_helper.py uses page.evaluate() to execute JavaScript within the browser context to perform operations such as accessing local storage or highlighting UI elements.
  • Evidence: Functions like get_local_storage, set_local_storage, and highlight_element use Python f-strings to interpolate variables directly into JavaScript strings (e.g., self.page.evaluate(f"localStorage.getItem('{key}')")).
  • Risk: This implementation creates a risk of JavaScript injection if the input parameters (such as the storage key or element selector) are derived from untrusted sources without proper sanitization.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from arbitrary web pages and API responses, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Content is extracted using methods like get_text, get_form_data, and get_performance_metrics in scripts/playwright_helper.py, as well as standard locator interactions in scripts/test_examples.py.
  • Boundary markers: The skill does not implement delimiters or specific instructions for the agent to ignore potentially malicious commands embedded in the processed data.
  • Capability inventory: The skill has the capability to perform network requests (page.goto), write files (page.screenshot, download.save_as), and execute JavaScript in the browser context.
  • Sanitization: No explicit sanitization or filtering of the extracted content is performed before it is provided to the agent's context.
  • [EXTERNAL_DOWNLOADS]: The documentation and setup guides instruct users to run playwright install to fetch browser binaries for Chromium, Firefox, and WebKit.
  • Evidence: This behavior is documented in README.md, SKILL.md, and references/setup-configuration.md.
  • Context: These downloads are standard requirements for the Playwright framework and originate from official distribution channels.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — webapp-testing