playwright-testing
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [DATA_EXFILTRATION]: The 'Companion check' section in
SKILL.mdinstructs the agent to perform reconnaissance by scanning multiple home directory paths (~/.claude/skills/,~/.agent/skills/, etc.) to detect other installed skills. This allows the skill to gather metadata about the user's environment to provide recommendations. - [COMMAND_EXECUTION]: The script
scripts/diagnose-flaky.shutilizesnode -eto execute a dynamically constructed JavaScript block for parsing JSON test reports and updating a local run log. While intended for diagnosis, this pattern involves dynamic code execution on the local system. - [COMMAND_EXECUTION]: The
scripts/setup-project.shscript automates project initialization by runningnpm installandnpx playwright install, which downloads and executes external packages and binaries from public registries. - [DATA_EXFILTRATION]: The skill manages sensitive authentication state files (e.g.,
.auth/user.jsoncontaining session cookies). Whilereferences/auth-patterns.mdprovides correct guidance on ignoring these files in version control, the skill's operational model involves handling these credentials locally.
Audit Metadata