playwright-cli

Fail

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill allows for the execution of arbitrary JavaScript/TypeScript through the run-code command and page-level JS via eval. This enables an attacker to run custom scripts if the agent is compromised or misled. Evidence: playwright-cli run-code command in references/running-code.md and playwright-cli eval command in SKILL.md.
  • [DATA_EXFILTRATION]: The skill provides explicit mechanisms to extract sensitive browser states, cookies, and clipboard data. Evidence: playwright-cli state-save auth.json for harvesting authentication states and example in references/running-code.md showing clipboard extraction via navigator.clipboard.readText().
  • [EXTERNAL_DOWNLOADS]: The skill includes commands that download and install external components without explicit integrity verification in the documentation. Evidence: playwright-cli install --skills and playwright-cli install-browser in SKILL.md.
  • [COMMAND_EXECUTION]: The skill's functionality is exposed through a command-line interface that executes shell commands to interact with browser processes. Evidence: All playwright-cli commands listed in SKILL.md.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core purpose of processing untrusted web content using high-privilege tools. Ingestion points: playwright-cli open and playwright-cli goto in SKILL.md. Boundary markers: None identified. Capability inventory: run-code, eval, state-save, download.saveAs. Sanitization: No evidence of input sanitization or output validation for web content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 6, 2026, 03:10 PM
Security Audit — agent-trust-hub — playwright-cli