playwright
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection from the web pages it interacts with during end-to-end testing.\n
- Ingestion points: Reads data from web application UI elements such as labels, text, and attributes as defined in SKILL.md (Step 2).\n
- Boundary markers: No explicit boundary markers or instructions to ignore embedded commands in page content are provided.\n
- Capability inventory: Executes shell commands via npx (SKILL.md, Step 7) and writes session state to the local filesystem (SKILL.md, Step 5).\n
- Sanitization: Content retrieved from pages is not sanitized or validated before being used to drive agent interactions.\n- [EXTERNAL_DOWNLOADS]: Fetches browser binaries via
npx playwright install. These are retrieved from Microsoft's official distribution infrastructure as part of the standard Playwright setup.\n- [COMMAND_EXECUTION]: Executesnpx playwright testto validate test suites. This is the primary intended function of the skill and utilizes standard, well-documented development tooling.
Audit Metadata