playwright-verifier

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill utilizes external data which establishes an attack surface for indirect prompt injection.
  • Ingestion points: The skill accepts untrusted parameters including url (dev server URL) and selector (CSS selector) in SKILL.md under the 'Receive Fix Context' step.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the ingested content are present.
  • Capability inventory: The skill possesses browser automation capabilities through Playwright, enabling it to navigate to provided URLs and interact with page elements.
  • Sanitization: There are no instructions provided for the validation or sanitization of input URLs or selectors before they are used in automation tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 09:33 PM