playwright-draft-filler

Warn

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/discover-selectors.mjs is vulnerable to shell command injection.
  • It uses child_process.spawn with shell: true to execute npx playwright codegen using a URL passed directly from command-line arguments.
  • Because the URL argument is not validated or escaped, an attacker could provide a crafted URL containing shell metacharacters (such as ;, &, or |) to execute arbitrary commands on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill's architecture creates an attack surface for indirect prompt injection when processing external web pages.
  • Ingestion points: The agent is instructed to navigate to a user-specified TARGET_URL and read data from a data.json file in scripts/draft-fill-template.mjs.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between form-filling tasks and potential instructions embedded within the target website's content.
  • Capability inventory: The skill possesses capabilities for file system writes (writeFileSync), full browser control via Playwright, and shell process spawning (spawn).
  • Sanitization: No validation, escaping, or sanitization is performed on the input URL or the data values before they are used in browser automation or shell command contexts.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external software packages and binaries.
  • The setup workflow includes npm install for the Playwright framework and npx playwright install to download browser engines.
  • These downloads are performed from well-known technology services (NPM and Microsoft) and are part of the intended project setup.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 17, 2026, 01:13 PM