playwright-interactive
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructions explicitly recommend starting the agent with the
--sandbox danger-full-accessflag. This configuration disables the primary security boundary, granting the agent unrestricted access to the host system. While this is noted as a temporary requirement for Playwright support, it presents a significant security risk if the agent is subsequently exposed to malicious content. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external applications and web pages via
page.goto(TARGET_URL), which exposes the agent to untrusted data that could contain malicious instructions. - Ingestion points: The agent navigates to and reads content from arbitrary URLs and local applications using Playwright in
SKILL.md. - Boundary markers: No explicit delimiters or boundary instructions are used to separate untrusted web content from the agent's core instructions.
- Capability inventory: The skill utilizes
js_replfor arbitrary code execution, performs network operations, and requests full filesystem/shell access via the sandbox bypass. - Sanitization: The skill does not implement automated sanitization of content retrieved from the browser; instead, it relies on human review and a manual signoff process.
- [COMMAND_EXECUTION]: The setup instructions include standard commands to install dependencies such as
playwrightandelectron, as well as browser binaries usingnpx playwright install chromium. - [DYNAMIC_EXECUTION]: The skill uses
page.evaluate()andelectronApp.evaluate()to execute JavaScript within the browser or Electron renderer process. This is primarily used for legitimate UI inspection, coordinate mapping, and screenshot normalization.
Audit Metadata