true-dom-tester

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and provides instructions for installing official packages from well-known services.
  • It suggests installing @mendable/firecrawl-js (NPM) and firecrawl-py (PyPI), which are official libraries for the Firecrawl scraping service.
  • [COMMAND_EXECUTION]: The skill uses Bash to execute Playwright commands and its own playwright-cli for interacting with the browser DOM.
  • The execution is scoped to the primary purpose of the skill (automated testing).
  • Commands like npx playwright test and npx firecrawl scrape are standard for the intended workflow.
  • [DATA_EXPOSURE]: The skill handles potential secrets (API keys) following security best practices.
  • Documentation in references/firecrawl.md and references/examples.md correctly demonstrates using environment variables (process.env.FIRECRAWL_API_KEY) and provides generic placeholders (fc-...) rather than hardcoded credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites by reading the DOM's accessibility tree.
  • Ingestion points: playwright-cli snapshot reads the content of target URLs into the agent's context in SKILL.md.
  • Boundary markers: The instructions guide the agent to interpret the tree structure for locator identification, but do not explicitly warn against malicious content in the DOM itself.
  • Capability inventory: The agent has Write and Bash access to generate and execute test scripts based on this data in SKILL.md and references/examples.md.
  • Sanitization: The skill relies on standard Playwright locator patterns which reduces the risk of malicious input influencing script execution, as the generated output is structured TypeScript code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 03:50 PM
Security Audit — agent-trust-hub — true-dom-tester