core-web-vitals
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses Playwright MCP tools for their intended purpose of navigating to and evaluating web pages. No evidence of malicious activity such as data exfiltration, credential harvesting, or persistent access was found.
- [PROMPT_INJECTION]: The skill navigates to external URLs, which represents a surface for indirect prompt injection. However, it is configured to extract only numeric performance metrics, minimizing risk.
- Ingestion points:
mcp__playwright__browser_navigateuses user-supplied URLs inSKILL.md. - Boundary markers: None.
- Capability inventory:
mcp__playwright__browser_navigate,mcp__playwright__browser_evaluate, andmcp__playwright__browser_clickare used inSKILL.md. - Sanitization: None.
Audit Metadata