playwright-expert
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill links to external documentation (https://jeffallan.github.io/claude-skills/skills/quality/playwright-expert/) that has been blacklisted by URL reputation scanners.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external application data, which presents a surface for indirect prompt injection. Ingestion points: The skill processes test reports (results.json), intercepted API responses (references/api-mocking.md), and execution traces (references/debugging-flaky.md). Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions found within tested web content or API payloads. Capability inventory: The skill supports shell command execution (npx playwright test), network mocking, and file system interactions for artifacts. Sanitization: No validation or sanitization routines are provided for handling dynamic content from the tested applications.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata