playwright-skill

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
  • [DYNAMIC_EXECUTION]: The run.js script implements a mechanism where JavaScript code provided as an argument, file, or via stdin is written to a temporary file in the skill directory (.temp-execution-*.js) and subsequently executed using the require() function. This facilitates the execution of arbitrary code within the agent's runtime environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract text and data from external websites and console logs. Because this external content is ingested into the agent's context without sanitization or protective boundary markers, it creates a vector for malicious instructions embedded in web pages (Category 8a/8c) to influence subsequent agent behavior.
  • [DATA_EXPOSURE]: The lib/helpers.js file contains a detectDevServers function that probes a predefined list of common ports (3000, 3001, 8080, etc.) on localhost. This performs local network reconnaissance and exposes the presence of local services to the agent.
  • [COMMAND_EXECUTION]: The run.js utility uses child_process.execSync to automatically run npm install and npx playwright install if the Playwright dependency is missing, executing shell commands on the host system during the initialization phase.
  • [METADATA_POISONING]: There is a discrepancy between the author specified in package.json (lackeyjb) and the author context provided (claudiodearaujo), which may indicate misleading metadata.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — playwright-skill