playwright
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external websites via Playwright's automation and evaluation methods.
- Ingestion points: External URLs are accessed and processed in various scripts across reference documentation (e.g.,
references/testing-patterns.md,references/network-testing.md). - Boundary markers: There are no documented delimiters or specific instructions provided to the agent to isolate untrusted web content from its core logic.
- Capability inventory: The skill allows for the execution of CLI tools via
npx, file system writes for screenshots and session data (fs.writeFile,saveAs), and arbitrary network requests. - Sanitization: No specific mechanisms for sanitizing or validating data retrieved from external pages are mentioned before processing.
- [EXTERNAL_DOWNLOADS]: Recommends downloading browser binaries and using official Docker images from Microsoft (
mcr.microsoft.com). It also suggests using standard community plugins likeplaywright-extraandpuppeteer-extra-plugin-stealthfor anti-bot bypass. - [COMMAND_EXECUTION]: Provides instructions for running Playwright CLI commands (e.g.,
npx playwright test,npx playwright install) which perform shell-level operations for testing and environment setup.
Audit Metadata