playwriter

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx -y playwriter to download and execute the playwriter package from the npm registry. The -y flag skips installation confirmation, which can lead to the execution of untrusted code if the package name is typosquatted or the registry is compromised.
  • [COMMAND_EXECUTION]: The agent is instructed to run shell commands to create sessions and execute scripts using the playwriter CLI tool directly on the host machine.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates and executes JavaScript code within the browser context using the -e flag and page.evaluate(). This allows the agent to perform arbitrary actions and script execution inside the user's live Chrome tab, bypassing standard static code review.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads content directly from web pages (DOM, accessibility snapshots, console logs), which are untrusted external sources. A malicious website could contain hidden instructions that manipulate the agent's behavior when this data is ingested into the context.
  • Ingestion points: Live browser tab content and accessibility trees retrieved via the Playwriter CLI.
  • Boundary markers: Absent. The instructions do not specify any delimiters or safety warnings for the agent when processing ingested page content.
  • Capability inventory: The skill provides full shell access to the playwriter CLI and in-page script execution via page.evaluate.
  • Sanitization: No sanitization or filtering of the retrieved web content is implemented before it is returned to the agent context.
  • [DATA_EXFILTRATION]: The tool facilitates the extraction of potentially sensitive information from the user's browser tab, including URLs, page titles, and the full content of the page (via innerText and accessibilitySnapshot). While no direct network exfiltration is performed by the skill's specific code, the extracted data is made available to the agent for further processing or potential exfiltration.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 09:17 AM
Security Audit — agent-trust-hub — playwriter