playwright-cli
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPERSISTENCE
Full Analysis
- [DYNAMIC_EXECUTION]: The
run-codeandevalcommands allow the agent to execute arbitrary JavaScript code within the browser context, which can be used to manipulate page state, bypass client-side security, or access data not exposed through standard DOM APIs. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external web pages which may contain malicious instructions hidden in the DOM. It specifically encourages using 'WebMCP' tools which are provided directly by the untrusted web pages being browsed.
- Ingestion points:
playwright-cli snapshot,playwright-cli find,webmcp-list, andwebmcp-callingest content and schemas directly from external web pages into the agent's context. - Boundary markers: The documentation includes a conceptual warning to treat page-provided tools as untrusted, but no technical boundary markers or 'ignore embedded instructions' prompts are enforced.
- Capability inventory: The skill has access to shell commands (Bash), file system writes (
state-save,screenshot,video-start), and full network access through the browser environment. - Sanitization: There is no mention of sanitization or filtering of external content before it is processed by the agent.
- [CREDENTIALS_UNSAFE]: The skill provides explicit functionality to extract and manage sensitive session data. Commands such as
cookie-get,localstorage-get, andsessionstorage-getcan expose session identifiers, whilestate-savewrites the entire authenticated browser state to a local JSON file. - [EXTERNAL_DOWNLOADS]: The skill instructions suggest installing external packages from NPM (
@playwright/cli@latest) and usingnpxto execute the Playwright test runner. While Playwright is a well-known tool, the specific package name mentioned (@playwright/cli) is not the standard primary package for the project. - [PERSISTENCE]: The skill includes functionality to maintain browser sessions across tasks through
state-saveandstate-loadcommands, as well as the--persistentflag for browser profiles, which allows for the long-term storage of session credentials and browser history on the host system.
Audit Metadata