playwright-interactive

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructions explicitly recommend starting the agent with the --sandbox danger-full-access flag. This configuration disables the primary security boundary, granting the agent unrestricted access to the host system. While this is noted as a temporary requirement for Playwright support, it presents a significant security risk if the agent is subsequently exposed to malicious content.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external applications and web pages via page.goto(TARGET_URL), which exposes the agent to untrusted data that could contain malicious instructions.
  • Ingestion points: The agent navigates to and reads content from arbitrary URLs and local applications using Playwright in SKILL.md.
  • Boundary markers: No explicit delimiters or boundary instructions are used to separate untrusted web content from the agent's core instructions.
  • Capability inventory: The skill utilizes js_repl for arbitrary code execution, performs network operations, and requests full filesystem/shell access via the sandbox bypass.
  • Sanitization: The skill does not implement automated sanitization of content retrieved from the browser; instead, it relies on human review and a manual signoff process.
  • [COMMAND_EXECUTION]: The setup instructions include standard commands to install dependencies such as playwright and electron, as well as browser binaries using npx playwright install chromium.
  • [DYNAMIC_EXECUTION]: The skill uses page.evaluate() and electronApp.evaluate() to execute JavaScript within the browser or Electron renderer process. This is primarily used for legitimate UI inspection, coordinate mapping, and screenshot normalization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — playwright-interactive