playwright-skill

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The run.js script facilitates the execution of arbitrary Node.js code by writing input to a temporary file in the skill directory and loading it via the require() function.
  • [REMOTE_CODE_EXECUTION]: The skill architecture is based on the agent dynamically writing Playwright scripts to the /tmp directory and executing them via a wrapper, allowing for the execution of arbitrary logic.
  • [DATA_EXFILTRATION]: The detectDevServers helper in lib/helpers.js performs local network discovery by probing common development ports (3000, 3001, 3002, 5173, 8080, 8000, 4200, 5000, 9000, 1234) on localhost.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from external websites. Ingestion points: Data extracted using extractTexts and extractTableData in lib/helpers.js. Boundary markers: No delimiters or isolation warnings are used in the instructions or code. Capability inventory: Full Node.js execution and file system access. Sanitization: No validation or filtering is applied to web content before it enters the agent's context.
  • [EXTERNAL_DOWNLOADS]: The setup script in package.json and the run.js executor download the Playwright library and Chromium browser binaries from the official NPM registry and Playwright's distribution servers.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — playwright-skill