playwright-skill

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The run.js file implements a universal executor that takes arbitrary JavaScript code from command-line arguments or standard input, wraps it in a template, writes it to a temporary file in the skill directory, and executes it using require(). This facilitates the runtime execution of dynamically generated scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with and extract data from external websites, which makes it susceptible to instructions embedded in third-party content.
  • Ingestion points: Content from web pages accessed via page.goto(), extractTexts(), and extractTableData() in lib/helpers.js.
  • Boundary markers: There are no boundary markers or specific instructions to ignore embedded commands when processing external site data.
  • Capability inventory: Full browser control, file system writes (for screenshots and execution scripts), local port discovery via detectDevServers in lib/helpers.js, and general network access.
  • Sanitization: The skill does not filter or sanitize retrieved web content before processing.
  • [COMMAND_EXECUTION]: The setup script and run.js perform environment configuration by executing shell commands such as npm install and npx playwright install.
  • [EXTERNAL_DOWNLOADS]: The skill downloads the Playwright library and browser binaries from public registries during its setup phase.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — playwright-skill