managing-playwright-deep

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper function playwright_run executes npx playwright test $args. The use of unquoted $args allows for shell command injection if the agent provides unsanitized input derived from untrusted sources.\n- [EXTERNAL_DOWNLOADS]: The skill uses npx to execute Playwright, which may involve downloading packages and browser binaries from Microsoft's official registries. This is standard functionality for the Playwright framework.\n- [PROMPT_INJECTION]: The skill reads and parses playwright-report/report.json. As test titles, project names, and error messages within this report can be controlled by the code being tested, this creates a surface for indirect prompt injection where malicious test data could influence the agent's behavior.\n
  • Ingestion points: playwright-report/report.json (Phase 2: Analysis)\n
  • Boundary markers: None present.\n
  • Capability inventory: Shell execution via npx playwright test.\n
  • Sanitization: No validation or sanitization is performed on the JSON report content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-playwright-deep