playwright

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to automatically terminate (kill) existing Chrome processes without user intervention when launch conflicts occur.- [REMOTE_CODE_EXECUTION]: The skill utilizes high-capability tools including a run_code sandbox and browser_evaluate for executing JavaScript within the browser context.- [CREDENTIALS_UNSAFE]: The instructions identify that the mcp-chrome-* directories contain authentication cookies and strictly forbid their deletion, confirming the agent's access to sensitive user session credentials.- [PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection due to its interaction with untrusted external web content combined with powerful evaluation capabilities.
  • Ingestion points: The agent retrieves data from arbitrary external websites via navigation and DOM snapshots (SKILL.md).
  • Boundary markers: No specific delimiters or instructions are provided to help the agent distinguish between its system instructions and commands embedded in target web pages.
  • Capability inventory: The agent can execute code (run_code, browser_evaluate) and manage system processes (kill).
  • Sanitization: There is no evidence of content filtering or sanitization of the data ingested from the browser before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 02:54 PM
Security Audit — agent-trust-hub — playwright