playwright
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npx --package @playwright/cliinscripts/playwright_cli.shto fetch and run the Playwright CLI. It also prompts the user to install@playwright/clivianpmifnpxis unavailable. These actions target well-known package registries and developer tools. - [COMMAND_EXECUTION]: The script
scripts/playwright_cli.shexecutes theplaywright-clicommand with user-provided arguments. The skill also makes use ofevalandrun-codecommands to execute JavaScript in the browser context, which is necessary for its stated purpose of browser automation. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes content from arbitrary external websites using tools like
snapshotandeval. Malicious instructions embedded in a web page could be processed by the agent. - Ingestion points:
snapshotcommands andevaloutputs inSKILL.mdandreferences/cli.mdwhich read data from remote URLs. - Capability inventory: Shell command execution via
playwright_cli.sh, including browser controls (click, fill) and arbitrary JavaScript execution (eval,run-code). - Boundary markers: None present to distinguish extracted web content from agent instructions.
- Sanitization: None present; raw element text and page data are returned directly to the agent context.
Audit Metadata