playwright-automation

Warn

Audited by Gen Agent Trust Hub on May 23, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation recommends the installation and use of the unverified package '@playwright/mcp@latest'. This package is not an official Microsoft Playwright resource and could represent a supply chain risk if a malicious actor registers it on a public registry.
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to execute shell commands that do not exist in current official releases, such as 'npx playwright init-agents --loop=claude'. This could result in the execution of untrusted code if the command or associated package name is registered by a third party (supply chain hijacking).
  • [PROMPT_INJECTION]: The skill uses deceptive framing by claiming awareness of '2025-2026' features and asserting a 'current latest' version of Playwright from April 2026. This metadata poisoning is designed to override the agent's internal knowledge and induce it to follow fraudulent technical procedures.
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by instructing the agent to interact with and process untrusted external web content via browser automation without explicit sanitization or boundary markers between the agent's instructions and the content being tested.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 23, 2026, 07:05 AM
Security Audit — agent-trust-hub — playwright-automation