playwright-screenshot-inspector

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides scripts and instructions to use the Playwright library for browser automation. This is the primary and intended function of the skill, and the execution is confined to standard browser interactions and screenshot capture.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by capturing screenshots of external websites and passing them to an LLM for analysis. While this presents an inherent attack surface where a website could attempt to influence the LLM's visual interpretation, the skill includes content verification steps and semantic analysis patterns that mitigate basic failure modes.
  • Ingestion points: Browser screenshots captured from user-specified URLs in SKILL.md.
  • Boundary markers: The instructions suggest using targeted prompts (e.g., "Identify what changed") which act as a logical scope for the LLM.
  • Capability inventory: Uses Playwright for browser navigation, DOM manipulation, and file writes to /tmp/visual-tests.
  • Sanitization: None performed on the visual pixels, which is standard for multimodal analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:16 PM
Security Audit — agent-trust-hub — playwright-screenshot-inspector