playwright-compress
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill configures a hook to execute a local shell script (".claude/hooks/scripts/playwright-compress.sh") using bash to process tool outputs.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it summarizes untrusted data from web-crawling tools (Playwright/Chrome).
- Ingestion points: Data enters via output from "mcp__playwright__." and "mcp__claude-in-chrome__." tools.
- Boundary markers: No delimiters or safety instructions are specified to isolate untrusted content from the summarization model.
- Capability inventory: The skill executes shell scripts and modifies tool output in the agent context.
- Sanitization: No sanitization or filtering of external tool output is documented before processing.
Audit Metadata