browser-test-loop
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to install dependencies, start a local development server, and run Playwright test suites within
SKILL.md. - [EXTERNAL_DOWNLOADS]: The skill downloads the
@playwright/testpackage and Chromium browser binaries from official registries as part of the setup process inSKILL.md. These are industry-standard development resources. - [INDIRECT_PROMPT_INJECTION]: The skill processes terminal output and log files from the application being tested, which creates a surface where the agent could ingest instructions embedded in external output.
- Ingestion points: Terminal output from Playwright tests and application logs stored in
/tmp/dev.logmentioned inSKILL.md. - Boundary markers: No specific delimiters or safety instructions are provided to separate tool output from instructions.
- Capability inventory: The skill has access to the
BashandWritetools as defined in the frontmatter ofSKILL.md. - Sanitization: No filtering or sanitization steps are defined for the ingested log content.
Audit Metadata