browsing-with-playwright
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/mcp-client.pyscript usessubprocess.Popenwithshell=Trueto launch local MCP servers via the stdio transport. - Evidence:
scripts/mcp-client.pyline 147:self._process = subprocess.Popen(self.command, shell=True, ...) - [DYNAMIC_EXECUTION]: The skill exposes tools that allow for the execution of arbitrary JavaScript code within the browser context, which is a high-privilege capability.
- Evidence:
references/playwright-tools.mddefinesbrowser_run_codeandbrowser_evaluatetools which accept JavaScript strings for execution. - [DATA_EXFILTRATION]: The
browser_file_uploadtool allows the browser to upload files from absolute paths on the local system, which could be abused to exfiltrate sensitive data if the agent interacts with a malicious website. - Evidence:
references/playwright-tools.mddefines thebrowser_file_uploadtool which takes a list of absolute file paths. - [EXTERNAL_DOWNLOADS]: The skill fetches the Playwright MCP server from the official npm registry during the server startup process.
- Evidence:
scripts/start-server.shcontainsnpx @playwright/mcp@latest --port "$PORT" --shared-browser-context &. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with and extract data from external websites, creating a surface where malicious web content could influence the agent's behavior.
- Ingestion points: The
browser_snapshot,browser_evaluate, andbrowser_take_screenshottools inreferences/playwright-tools.mdingest data from web pages. - Boundary markers: No delimiters or explicit instructions to ignore embedded content were found in the provided files.
- Capability inventory: The skill has extensive capabilities including arbitrary JavaScript execution (
browser_run_code), file uploads (browser_file_upload), and full browser navigation. - Sanitization: There is no evidence of sanitization or filtering of external web content before it is returned to the agent's context.
Audit Metadata