playwright
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the
@playwright/clipackage from the official NPM registry vianpxto provide browser automation capabilities. - [COMMAND_EXECUTION]: Implements a shell wrapper script (
scripts/playwright_cli.sh) to facilitate browser interactions and session management through the Playwright CLI. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external websites, which presents a surface for indirect prompt injection.
- Ingestion points: Web content is read into the agent context through
pwcli snapshotandpwcli evalcommands (SKILL.md). - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded content in its instructions.
- Capability inventory: The skill has capabilities for network access, writing files (screenshots, PDFs, traces), and executing JavaScript within the browser context (SKILL.md, scripts/playwright_cli.sh).
- Sanitization: There is no explicit sanitization or filtering of external website content before it is processed by the agent.
Audit Metadata