browsing-with-playwright

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/mcp-client.py uses subprocess.Popen with shell=True to execute commands passed via the --stdio command-line argument, which could be misused to run arbitrary local commands.
  • Evidence: scripts/mcp-client.py line 166 contains subprocess.Popen(self.command, shell=True, ...) where self.command is user-provided.
  • [DYNAMIC_EXECUTION]: The skill provides tools for executing arbitrary code and JavaScript expressions within the browser environment, which allows for powerful but potentially dangerous runtime interactions.
  • Evidence: The browser_evaluate tool in references/playwright-tools.md accepts an arbitrary function string.
  • Evidence: The browser_run_code tool in references/playwright-tools.md executes a string of Playwright code.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with untrusted external web content and possesses high-privilege automation tools, creating a surface where malicious web pages could influence agent behavior.
  • Ingestion points: browser_snapshot in references/playwright-tools.md returns raw web page content.
  • Boundary markers: None identified in tool instructions to distinguish between instructions and data.
  • Capability inventory: browser_run_code, browser_evaluate, and various interaction tools (browser_click, browser_fill_form).
  • Sanitization: The skill does not explicitly describe any sanitization or filtering of content retrieved from the web.
  • [EXTERNAL_DOWNLOADS]: The skill downloads the Playwright MCP server from the npm registry using npx during initialization.
  • Evidence: SKILL.md and scripts/start-server.sh reference npx @playwright/mcp@latest.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 10:04 AM
Security Audit — agent-trust-hub — browsing-with-playwright