playwright-draft-filler
Warn
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/discover-selectors.mjsis vulnerable to shell command injection. - It uses
child_process.spawnwithshell: trueto executenpx playwright codegenusing a URL passed directly from command-line arguments. - Because the URL argument is not validated or escaped, an attacker could provide a crafted URL containing shell metacharacters (such as
;,&, or|) to execute arbitrary commands on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill's architecture creates an attack surface for indirect prompt injection when processing external web pages.
- Ingestion points: The agent is instructed to navigate to a user-specified
TARGET_URLand read data from adata.jsonfile inscripts/draft-fill-template.mjs. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between form-filling tasks and potential instructions embedded within the target website's content.
- Capability inventory: The skill possesses capabilities for file system writes (
writeFileSync), full browser control via Playwright, and shell process spawning (spawn). - Sanitization: No validation, escaping, or sanitization is performed on the input URL or the data values before they are used in browser automation or shell command contexts.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external software packages and binaries.
- The setup workflow includes
npm installfor the Playwright framework andnpx playwright installto download browser engines. - These downloads are performed from well-known technology services (NPM and Microsoft) and are part of the intended project setup.
Audit Metadata