managing-playwright-deep
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper function
playwright_runexecutesnpx playwright test $args. The use of unquoted$argsallows for shell command injection if the agent provides unsanitized input derived from untrusted sources.\n- [EXTERNAL_DOWNLOADS]: The skill usesnpxto execute Playwright, which may involve downloading packages and browser binaries from Microsoft's official registries. This is standard functionality for the Playwright framework.\n- [PROMPT_INJECTION]: The skill reads and parsesplaywright-report/report.json. As test titles, project names, and error messages within this report can be controlled by the code being tested, this creates a surface for indirect prompt injection where malicious test data could influence the agent's behavior.\n - Ingestion points:
playwright-report/report.json(Phase 2: Analysis)\n - Boundary markers: None present.\n
- Capability inventory: Shell execution via
npx playwright test.\n - Sanitization: No validation or sanitization is performed on the JSON report content before processing.
Audit Metadata