vector
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is primarily designed to scrape and process arbitrary web pages, creating a significant attack surface for indirect prompt injection where malicious instructions embedded in web content could influence the agent's behavior.
- Ingestion points: Web page content is ingested via
playwright_snapshot,get_page_text, and network response monitoring. - Boundary markers: The skill mentions
_common/WEB_FETCH_SAFETY.mdfor prompt-injection checks before content is summarized or relayed. - Capability inventory: The skill possesses extensive capabilities including writing to the
.vector/directory, making network requests via Playwright, and executing code throughplaywright_evaluateandbrowser_run_code. - Sanitization: While safety checks are mentioned, the inherent nature of processing untrusted HTML/DOM content is a persistent risk.
- [DYNAMIC_EXECUTION]: The skill utilizes tools that allow for the execution of arbitrary code within the browser context.
- Evidence:
playwright_evaluateis used to execute JavaScript (e.g., to pierce Shadow DOM or perform complex extractions), andbrowser_run_codeallows the execution of Playwright scripts directly. - Risk: If the agent generates these scripts based on untrusted input from a web page, it could lead to code execution within the browser environment.
- [COMMAND_EXECUTION]: The skill documentation encourages the use of the Playwright CLI over the MCP server for multi-step tasks to save tokens.
- Evidence: Mentions in
SKILL.mdandreference/computer-use-optimization.mdexplicitly advocate for the CLI path when filesystem access is available. - [EXTERNAL_DOWNLOADS]: The skill references a wide range of external tools and services for specialized tasks like stealth scraping and large-scale crawling.
- Evidence: Mentions of
curl-impersonate,bright-data,oxylabs, and CAPTCHA solving services like2CaptchaorAnti-Captchainreference/stealth-mode.mdandreference/crawl/anti-detection-architecture.md.
Audit Metadata