playwright-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a best-practices guide for Playwright testing. Analysis of all 59 files revealed no evidence of prompt injection, data exfiltration, or malicious persistence mechanisms.
- [SAFE]: Authentication patterns described in the skill follow industry standards, including the use of storage state for session reuse, instructions to exclude sensitive auth files from version control via
.gitignore, and the use of environment variables for credentials. - [SAFE]: External dependencies and script injections (e.g.,
web-vitalsfromunpkg.com) are from well-known, trusted services and are used for legitimate testing purposes like performance monitoring. - [SAFE]: Commands executed via
child_process(e.g., inglobal-setup.md) are standard development tasks such as database migrations and seeding within a local test environment.
Audit Metadata