playwright-testing
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted data from external web pages to generate automation scripts and execute tests.\n
- Ingestion points: Data is ingested from web page DOM and accessibility trees during browser exploration (referenced in
references/playwright.md).\n - Boundary markers: No boundary markers or isolation instructions were identified to separate external data from the agent's instructional context.\n
- Capability inventory: The agent can write local files and execute shell commands including
npx playwright testandpytest(documented inSKILL.md).\n - Sanitization: No sanitization or validation logic is present to filter malicious instructions embedded in the processed web content.\n- [COMMAND_EXECUTION]: The skill relies on executing shell commands for setup and test execution, such as
npm install,pip install, andplaywright install. These operations involve running scripts and binaries locally to manage the browser environment.\n- [EXTERNAL_DOWNLOADS]: The setup instructions include fetching Playwright browser binaries and necessary software dependencies from official package registries and Microsoft's infrastructure.
Audit Metadata