playwright
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill uses
npxto download and execute the@playwright/clipackage from the official npm registry. This is a standard method for running the tool without global installation and leverages a trusted technology vendor.\n- [DYNAMIC_EXECUTION]: The skill providesevalandrun-codecommands which allow for the execution of arbitrary JavaScript within the context of the automated browser. These functions are intended for automation tasks like DOM manipulation and data extraction.\n- [INDIRECT_PROMPT_INJECTION]: By automating a web browser and reading content from external sites, the skill possesses an inherent attack surface for indirect instructions embedded in web pages. The skill includes instructions to use stable references and explicit commands to mitigate reliability risks.
Audit Metadata