setup-playwright

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and analyzing a repository's existing infrastructure, including package manifests, configuration files, and scripts, to determine the optimal setup. This processing of untrusted repository data creates an attack surface where malicious natural language instructions embedded in those files could attempt to influence the agent's actions during the harness setup. \n
  • Ingestion Points: The 'Harness Workflow' explicitly instructs the agent to read repository instructions, package and lock files, and scripts (SKILL.md). \n
  • Capability Inventory: The skill is authorized to write configuration files and execute shell commands via package managers (npm, pnpm, yarn, pip, dotnet, maven) and the Playwright CLI. \n
  • Boundary Markers: The instructions do not explicitly include delimiters or 'ignore' commands for content found within the analyzed repository files. \n
  • Sanitization: No specific sanitization or validation logic is defined for the natural language content read from the repository. \n- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the Playwright runner, browser binaries, and ecosystem-specific plugins (such as @playwright/test and pytest-playwright). These resources are fetched from official package registries (npm, PyPI, NuGet, Maven Central) and originate from the well-known and trusted Microsoft Playwright project.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 05:58 PM
Security Audit — agent-trust-hub — setup-playwright