playwright-skill
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
run.jsutility implements a dynamic execution pattern by writing provided JavaScript code to a temporary file and loading it via Node.js'srequiremechanism. This allows the agent to execute arbitrary code for automation tasks, representing a significant capability for remote code execution if the agent's logic is compromised. - [COMMAND_EXECUTION]: The skill frequently uses shell commands for environment configuration and script execution. Specifically, the
run.jsscript invokesnpm installandnpx playwright installusingexecSyncto manage its own dependencies and the Playwright browser binaries. - [DATA_EXFILTRATION]: By design, the skill can navigate to any URL and extract information such as page text, table data, and screenshots. While the skill includes instructions to seek user approval for external sites, the technical ability to interact with the network and local file system (/tmp) provides a potential path for data exposure.
- [PROMPT_INJECTION]: The skill is a major surface for indirect prompt injection because it is designed to ingest and process untrusted data from the web (Category 8). Malicious instructions embedded in target websites could attempt to influence the agent's behavior during the automation flow. The skill documents explicit 'Garde-fous de sécurité' (security guardrails) to mitigate this, including restrictions on visiting sensitive portals and guidelines against hardcoding real credentials.
Audit Metadata