skills/mabhub/skills/playwright-skill/Gen Agent Trust Hub

playwright-skill

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The run.js utility implements a dynamic execution pattern by writing provided JavaScript code to a temporary file and loading it via Node.js's require mechanism. This allows the agent to execute arbitrary code for automation tasks, representing a significant capability for remote code execution if the agent's logic is compromised.
  • [COMMAND_EXECUTION]: The skill frequently uses shell commands for environment configuration and script execution. Specifically, the run.js script invokes npm install and npx playwright install using execSync to manage its own dependencies and the Playwright browser binaries.
  • [DATA_EXFILTRATION]: By design, the skill can navigate to any URL and extract information such as page text, table data, and screenshots. While the skill includes instructions to seek user approval for external sites, the technical ability to interact with the network and local file system (/tmp) provides a potential path for data exposure.
  • [PROMPT_INJECTION]: The skill is a major surface for indirect prompt injection because it is designed to ingest and process untrusted data from the web (Category 8). Malicious instructions embedded in target websites could attempt to influence the agent's behavior during the automation flow. The skill documents explicit 'Garde-fous de sécurité' (security guardrails) to mitigate this, including restrictions on visiting sensitive portals and guidelines against hardcoding real credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 04:08 PM
Security Audit — agent-trust-hub — playwright-skill