playwright-automation-fill-in-form
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill interacts with an external web service which presents a surface for indirect prompt injection. Ingestion points: External content from forms.microsoft.com (SKILL.md). Boundary markers: Absent. Capability inventory: Playwright browser automation (navigation, form input, file upload). Sanitization: Absent.
- [DATA_EXFILTRATION]: The skill instructs the agent to upload a file from an absolute local path (/Users/myuserName/Downloads/my-image.png) to an external service. Accessing files within the user's directory structure involves risk if the agent is directed to sensitive files during automation.
Audit Metadata