skills/letta-ai/skills/playwright/Gen Agent Trust Hub

playwright

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the @playwright/cli package from the official NPM registry via npx to provide browser automation capabilities.
  • [COMMAND_EXECUTION]: Implements a shell wrapper script (scripts/playwright_cli.sh) to facilitate browser interactions and session management through the Playwright CLI.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external websites, which presents a surface for indirect prompt injection.
  • Ingestion points: Web content is read into the agent context through pwcli snapshot and pwcli eval commands (SKILL.md).
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded content in its instructions.
  • Capability inventory: The skill has capabilities for network access, writing files (screenshots, PDFs, traces), and executing JavaScript within the browser context (SKILL.md, scripts/playwright_cli.sh).
  • Sanitization: There is no explicit sanitization or filtering of external website content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — playwright