playwright-automation-fill-in-form

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill interacts with an external web service which presents a surface for indirect prompt injection. Ingestion points: External content from forms.microsoft.com (SKILL.md). Boundary markers: Absent. Capability inventory: Playwright browser automation (navigation, form input, file upload). Sanitization: Absent.
  • [DATA_EXFILTRATION]: The skill instructs the agent to upload a file from an absolute local path (/Users/myuserName/Downloads/my-image.png) to an external service. Accessing files within the user's directory structure involves risk if the agent is directed to sensitive files during automation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 02:13 PM
Security Audit — agent-trust-hub — playwright-automation-fill-in-form