browsing-with-playwright
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/mcp-client.pyusessubprocess.Popenwithshell=Trueto execute commands passed via the--stdiocommand-line argument, which could be misused to run arbitrary local commands. - Evidence:
scripts/mcp-client.pyline 166 containssubprocess.Popen(self.command, shell=True, ...)whereself.commandis user-provided. - [DYNAMIC_EXECUTION]: The skill provides tools for executing arbitrary code and JavaScript expressions within the browser environment, which allows for powerful but potentially dangerous runtime interactions.
- Evidence: The
browser_evaluatetool inreferences/playwright-tools.mdaccepts an arbitraryfunctionstring. - Evidence: The
browser_run_codetool inreferences/playwright-tools.mdexecutes a string of Playwright code. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with untrusted external web content and possesses high-privilege automation tools, creating a surface where malicious web pages could influence agent behavior.
- Ingestion points:
browser_snapshotinreferences/playwright-tools.mdreturns raw web page content. - Boundary markers: None identified in tool instructions to distinguish between instructions and data.
- Capability inventory:
browser_run_code,browser_evaluate, and various interaction tools (browser_click,browser_fill_form). - Sanitization: The skill does not explicitly describe any sanitization or filtering of content retrieved from the web.
- [EXTERNAL_DOWNLOADS]: The skill downloads the Playwright MCP server from the npm registry using
npxduring initialization. - Evidence:
SKILL.mdandscripts/start-server.shreferencenpx @playwright/mcp@latest.
Audit Metadata