browsing-with-playwright

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/mcp-client.py script uses subprocess.Popen with shell=True to launch local MCP servers via the stdio transport.
  • Evidence: scripts/mcp-client.py line 147: self._process = subprocess.Popen(self.command, shell=True, ...)
  • [DYNAMIC_EXECUTION]: The skill exposes tools that allow for the execution of arbitrary JavaScript code within the browser context, which is a high-privilege capability.
  • Evidence: references/playwright-tools.md defines browser_run_code and browser_evaluate tools which accept JavaScript strings for execution.
  • [DATA_EXFILTRATION]: The browser_file_upload tool allows the browser to upload files from absolute paths on the local system, which could be abused to exfiltrate sensitive data if the agent interacts with a malicious website.
  • Evidence: references/playwright-tools.md defines the browser_file_upload tool which takes a list of absolute file paths.
  • [EXTERNAL_DOWNLOADS]: The skill fetches the Playwright MCP server from the official npm registry during the server startup process.
  • Evidence: scripts/start-server.sh contains npx @playwright/mcp@latest --port "$PORT" --shared-browser-context &.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with and extract data from external websites, creating a surface where malicious web content could influence the agent's behavior.
  • Ingestion points: The browser_snapshot, browser_evaluate, and browser_take_screenshot tools in references/playwright-tools.md ingest data from web pages.
  • Boundary markers: No delimiters or explicit instructions to ignore embedded content were found in the provided files.
  • Capability inventory: The skill has extensive capabilities including arbitrary JavaScript execution (browser_run_code), file uploads (browser_file_upload), and full browser navigation.
  • Sanitization: There is no evidence of sanitization or filtering of external web content before it is returned to the agent's context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 08:02 AM
Security Audit — agent-trust-hub — browsing-with-playwright