playwriter
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npx -y playwriterto download and execute theplaywriterpackage from the npm registry. The-yflag skips installation confirmation, which can lead to the execution of untrusted code if the package name is typosquatted or the registry is compromised. - [COMMAND_EXECUTION]: The agent is instructed to run shell commands to create sessions and execute scripts using the
playwriterCLI tool directly on the host machine. - [DYNAMIC_EXECUTION]: The skill dynamically generates and executes JavaScript code within the browser context using the
-eflag andpage.evaluate(). This allows the agent to perform arbitrary actions and script execution inside the user's live Chrome tab, bypassing standard static code review. - [INDIRECT_PROMPT_INJECTION]: The skill reads content directly from web pages (DOM, accessibility snapshots, console logs), which are untrusted external sources. A malicious website could contain hidden instructions that manipulate the agent's behavior when this data is ingested into the context.
- Ingestion points: Live browser tab content and accessibility trees retrieved via the Playwriter CLI.
- Boundary markers: Absent. The instructions do not specify any delimiters or safety warnings for the agent when processing ingested page content.
- Capability inventory: The skill provides full shell access to the
playwriterCLI and in-page script execution viapage.evaluate. - Sanitization: No sanitization or filtering of the retrieved web content is implemented before it is returned to the agent context.
- [DATA_EXFILTRATION]: The tool facilitates the extraction of potentially sensitive information from the user's browser tab, including URLs, page titles, and the full content of the page (via
innerTextandaccessibilitySnapshot). While no direct network exfiltration is performed by the skill's specific code, the extracted data is made available to the agent for further processing or potential exfiltration.
Audit Metadata