playwright-expert

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill links to external documentation (https://jeffallan.github.io/claude-skills/skills/quality/playwright-expert/) that has been blacklisted by URL reputation scanners.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external application data, which presents a surface for indirect prompt injection. Ingestion points: The skill processes test reports (results.json), intercepted API responses (references/api-mocking.md), and execution traces (references/debugging-flaky.md). Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions found within tested web content or API payloads. Capability inventory: The skill supports shell command execution (npx playwright test), network mocking, and file system interactions for artifacts. Sanitization: No validation or sanitization routines are provided for handling dynamic content from the tested applications.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:39 AM
Security Audit — agent-trust-hub — playwright-expert