playwright-cli
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]:
- The skill documentation and reference files (specifically
references/running-code.md) promote the use ofplaywright-cli run-codeandplaywright-cli evalto execute arbitrary JavaScript code within the browser context to handle complex workflows like geolocation, permission management, and custom scraping. - These commands allow the execution of logic generated at runtime, which is a powerful capability necessary for the skill's primary function but inherently risky if misused.
- [INDIRECT_PROMPT_INJECTION]:
- The skill is designed to navigate to and process content from external, untrusted web pages through commands like
playwright-cli gotoandplaywright-cli snapshot. - Ingestion points: Data enters the agent's context via DOM snapshots (
playwright-cli snapshot), console logs (playwright-cli console), and network activity logs (playwright-cli requests) as described inSKILL.mdandreferences/tracing.md. - Boundary markers: The skill documentation uses standard markdown and YAML formatting to present browser data to the agent, providing structure but not preventing the agent from interpreting embedded instructions.
- Capability inventory: The skill possesses powerful capabilities including arbitrary JavaScript execution (
run-code), file writing (state-save,screenshot,pdf), and active browser interaction (click,fill,type). - Sanitization: The instructions do not explicitly guide the agent to sanitize or ignore instructions potentially embedded within the web content it retrieves.
- [EXTERNAL_DOWNLOADS]:
- The
SKILL.mdfile provides instructions for installing the Playwright CLI usingnpm install -g @playwright/cli@latest, which fetches resources from the official NPM registry. - [COMMAND_EXECUTION]:
- The skill extensively utilizes shell commands such as
playwright-cli,npx playwright test, andnpmto perform browser automation and testing tasks, as specified in theallowed-toolsmetadata.
Audit Metadata