playwright-e2e

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill contains strong instructions that override standard agent behavior. Specifically, it commands the agent to 'Monitor automatically' and 'Never ask to continue,' as well as 'NEVER RETURN BEFORE CI COMPLETES.' While these are intended to facilitate automation, they represent a bypass of typical interactive guardrails.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze external artifacts generated by CI/CD workflows, such as HTML reports and trace files. This creates an attack surface where malicious data embedded in test failures could attempt to influence the agent's logic.
  • Ingestion points: Artifacts are downloaded via gh run download and processed from .e2e-artifacts/, including playwright-report/index.html and JSONL span files.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions embedded within the processed test results.
  • Capability inventory: The skill utilizes several powerful tools including gh CLI, npm, ffmpeg, and python3 for processing data and managing local environments.
  • Sanitization: There is no evidence of content sanitization or validation for the downloaded HTML reports or log files before the agent analyzes them.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a variety of shell commands for testing and environment management. This includes npm run test, gh run list/watch/download, and cleanup commands like lsof -ti :3000 | xargs kill -9. These are standard for the described use case but involve direct manipulation of local processes.
  • [DYNAMIC_EXECUTION]: In references/analyze-e2e.md, the skill provides a Python script executed via a heredoc (`python3
  • <<'PY'`) to parse local JSONL files. This is a form of dynamic code execution managed by the agent's environment.
  • [EXTERNAL_DOWNLOADS]: The skill relies on downloading workflow artifacts from GitHub using the gh CLI. While GitHub is a well-known service, this involves pulling external data into the local environment for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:04 AM
Security Audit — agent-trust-hub — playwright-e2e