playwright-testing

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted data from external web pages to generate automation scripts and execute tests.\n
  • Ingestion points: Data is ingested from web page DOM and accessibility trees during browser exploration (referenced in references/playwright.md).\n
  • Boundary markers: No boundary markers or isolation instructions were identified to separate external data from the agent's instructional context.\n
  • Capability inventory: The agent can write local files and execute shell commands including npx playwright test and pytest (documented in SKILL.md).\n
  • Sanitization: No sanitization or validation logic is present to filter malicious instructions embedded in the processed web content.\n- [COMMAND_EXECUTION]: The skill relies on executing shell commands for setup and test execution, such as npm install, pip install, and playwright install. These operations involve running scripts and binaries locally to manage the browser environment.\n- [EXTERNAL_DOWNLOADS]: The setup instructions include fetching Playwright browser binaries and necessary software dependencies from official package registries and Microsoft's infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 07:18 AM
Security Audit — agent-trust-hub — playwright-testing