playwright
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto dynamically fetch and execute the@playwright/clipackage from the npm registry. This package is maintained by Microsoft, a well-known and trusted organization, and is used here for its intended purpose of browser automation. - [COMMAND_EXECUTION]: The wrapper script
scripts/playwright_cli.shfacilitates the execution of shell commands by passing user-supplied arguments directly tonpx. This is necessary for the CLI's operation but requires the agent to handle inputs carefully. - [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection. Because it automates a browser to visit external websites and extracts data (via
snapshotandeval) to guide its next steps, a malicious website could embed instructions in its DOM to subvert the agent's behavior. - Ingestion points: Browser snapshots and DOM evaluations performed by
pwcli snapshotandpwcli evalinSKILL.mdandreferences/workflows.md. - Boundary markers: None present. The skill does not instruct the agent to distinguish between its own logic and instructions that might be found within the web pages it visits.
- Capability inventory: The skill can interact with the browser (click, type, fill) and execute arbitrary JavaScript within the page context (
pwcli run-code,pwcli eval). - Sanitization: No sanitization of the content retrieved from the browser is performed before the agent processes it.
Audit Metadata