playwright-skill
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The
run.jsscript facilitates the execution of arbitrary Node.js code by writing input to a temporary file in the skill directory and loading it via therequire()function. - [REMOTE_CODE_EXECUTION]: The skill architecture is based on the agent dynamically writing Playwright scripts to the
/tmpdirectory and executing them via a wrapper, allowing for the execution of arbitrary logic. - [DATA_EXFILTRATION]: The
detectDevServershelper inlib/helpers.jsperforms local network discovery by probing common development ports (3000, 3001, 3002, 5173, 8080, 8000, 4200, 5000, 9000, 1234) onlocalhost. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from external websites. Ingestion points: Data extracted using
extractTextsandextractTableDatainlib/helpers.js. Boundary markers: No delimiters or isolation warnings are used in the instructions or code. Capability inventory: Full Node.js execution and file system access. Sanitization: No validation or filtering is applied to web content before it enters the agent's context. - [EXTERNAL_DOWNLOADS]: The
setupscript inpackage.jsonand therun.jsexecutor download the Playwright library and Chromium browser binaries from the official NPM registry and Playwright's distribution servers.
Audit Metadata