playwright-generate-test

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill generates TypeScript code and executes it using the Playwright runner. This runtime execution of generated code is the primary function of the skill but represents an inherent risk when the generation is driven by untrusted data.
  • Evidence: Instructions to 'emit a Playwright TypeScript test' and 'Execute the test file' in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it ingests untrusted user scenarios and uses them to generate executable logic.
  • Ingestion points: User scenario input mentioned in SKILL.md.
  • Boundary markers: None identified; the skill does not use delimiters or instructions to isolate the user scenario or prevent it from containing malicious code fragments.
  • Capability inventory: File writing ('Save generated test file') and command execution ('Execute the test file') as seen in SKILL.md.
  • Sanitization: No sanitization or validation of the input scenario is performed before code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:26 AM