playwright-cli

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides run-code and eval commands that allow for the execution of arbitrary JavaScript code within the browser context. This capability can be used to perform complex operations not covered by standard commands, but also allows for the execution of untrusted logic if the agent's input is compromised.
  • [EXTERNAL_DOWNLOADS]: The playwright-cli install and playwright-cli install-browser commands are used to download and install external browser binaries and potentially other skill-related components from remote sources.
  • [DATA_EXFILTRATION]: The skill includes comprehensive tools for accessing sensitive browser data, such as cookie-get, localstorage-get, and state-save. These tools can be used to extract authentication tokens and session data from websites.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is designed to ingest and process content from external, untrusted websites.
  • Ingestion points: Web page content is brought into the agent's context through snapshot, eval, run-code, and console logs.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the provided documentation.
  • Capability inventory: The skill possesses extensive capabilities including network navigation (goto), file writing (screenshot, pdf, state-save), and arbitrary code execution (run-code).
  • Sanitization: There is no evidence of sanitization or filtering of web content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill acts as a wrapper for the playwright-cli tool, executing shell commands to perform browser automation tasks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — playwright-cli