playwright-testing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The 'Companion check' section in SKILL.md instructs the agent to perform reconnaissance by scanning multiple home directory paths (~/.claude/skills/, ~/.agent/skills/, etc.) to detect other installed skills. This allows the skill to gather metadata about the user's environment to provide recommendations.
  • [COMMAND_EXECUTION]: The script scripts/diagnose-flaky.sh utilizes node -e to execute a dynamically constructed JavaScript block for parsing JSON test reports and updating a local run log. While intended for diagnosis, this pattern involves dynamic code execution on the local system.
  • [COMMAND_EXECUTION]: The scripts/setup-project.sh script automates project initialization by running npm install and npx playwright install, which downloads and executes external packages and binaries from public registries.
  • [DATA_EXFILTRATION]: The skill manages sensitive authentication state files (e.g., .auth/user.json containing session cookies). While references/auth-patterns.md provides correct guidance on ignoring these files in version control, the skill's operational model involves handling these credentials locally.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — playwright-testing