playwright-cli
Fail
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill allows for the execution of arbitrary JavaScript/TypeScript through the run-code command and page-level JS via eval. This enables an attacker to run custom scripts if the agent is compromised or misled. Evidence: playwright-cli run-code command in references/running-code.md and playwright-cli eval command in SKILL.md.
- [DATA_EXFILTRATION]: The skill provides explicit mechanisms to extract sensitive browser states, cookies, and clipboard data. Evidence: playwright-cli state-save auth.json for harvesting authentication states and example in references/running-code.md showing clipboard extraction via navigator.clipboard.readText().
- [EXTERNAL_DOWNLOADS]: The skill includes commands that download and install external components without explicit integrity verification in the documentation. Evidence: playwright-cli install --skills and playwright-cli install-browser in SKILL.md.
- [COMMAND_EXECUTION]: The skill's functionality is exposed through a command-line interface that executes shell commands to interact with browser processes. Evidence: All playwright-cli commands listed in SKILL.md.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core purpose of processing untrusted web content using high-privilege tools. Ingestion points: playwright-cli open and playwright-cli goto in SKILL.md. Boundary markers: None identified. Capability inventory: run-code, eval, state-save, download.saveAs. Sanitization: No evidence of input sanitization or output validation for web content.
Recommendations
- AI detected serious security threats
Audit Metadata