playwright-e2e
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill contains strong instructions that override standard agent behavior. Specifically, it commands the agent to 'Monitor automatically' and 'Never ask to continue,' as well as 'NEVER RETURN BEFORE CI COMPLETES.' While these are intended to facilitate automation, they represent a bypass of typical interactive guardrails.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze external artifacts generated by CI/CD workflows, such as HTML reports and trace files. This creates an attack surface where malicious data embedded in test failures could attempt to influence the agent's logic.
- Ingestion points: Artifacts are downloaded via
gh run downloadand processed from.e2e-artifacts/, includingplaywright-report/index.htmland JSONL span files. - Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions embedded within the processed test results.
- Capability inventory: The skill utilizes several powerful tools including
ghCLI,npm,ffmpeg, andpython3for processing data and managing local environments. - Sanitization: There is no evidence of content sanitization or validation for the downloaded HTML reports or log files before the agent analyzes them.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a variety of shell commands for testing and environment management. This includes
npm run test,gh run list/watch/download, and cleanup commands likelsof -ti :3000 | xargs kill -9. These are standard for the described use case but involve direct manipulation of local processes. - [DYNAMIC_EXECUTION]: In
references/analyze-e2e.md, the skill provides a Python script executed via a heredoc (`python3 - <<'PY'`) to parse local JSONL files. This is a form of dynamic code execution managed by the agent's environment.
- [EXTERNAL_DOWNLOADS]: The skill relies on downloading workflow artifacts from GitHub using the
ghCLI. While GitHub is a well-known service, this involves pulling external data into the local environment for analysis.
Audit Metadata