playwright

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to dynamically fetch and execute the @playwright/cli package from the npm registry. This package is maintained by Microsoft, a well-known and trusted organization, and is used here for its intended purpose of browser automation.
  • [COMMAND_EXECUTION]: The wrapper script scripts/playwright_cli.sh facilitates the execution of shell commands by passing user-supplied arguments directly to npx. This is necessary for the CLI's operation but requires the agent to handle inputs carefully.
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection. Because it automates a browser to visit external websites and extracts data (via snapshot and eval) to guide its next steps, a malicious website could embed instructions in its DOM to subvert the agent's behavior.
  • Ingestion points: Browser snapshots and DOM evaluations performed by pwcli snapshot and pwcli eval in SKILL.md and references/workflows.md.
  • Boundary markers: None present. The skill does not instruct the agent to distinguish between its own logic and instructions that might be found within the web pages it visits.
  • Capability inventory: The skill can interact with the browser (click, type, fill) and execute arbitrary JavaScript within the page context (pwcli run-code, pwcli eval).
  • Sanitization: No sanitization of the content retrieved from the browser is performed before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 07:18 AM
Security Audit — agent-trust-hub — playwright