playwright-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a best-practices guide for Playwright testing. Analysis of all 59 files revealed no evidence of prompt injection, data exfiltration, or malicious persistence mechanisms.
  • [SAFE]: Authentication patterns described in the skill follow industry standards, including the use of storage state for session reuse, instructions to exclude sensitive auth files from version control via .gitignore, and the use of environment variables for credentials.
  • [SAFE]: External dependencies and script injections (e.g., web-vitals from unpkg.com) are from well-known, trusted services and are used for legitimate testing purposes like performance monitoring.
  • [SAFE]: Commands executed via child_process (e.g., in global-setup.md) are standard development tasks such as database migrations and seeding within a local test environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:45 AM
Security Audit — agent-trust-hub — playwright-best-practices