playwright-test-data-isolation

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements patterns that ingest data from external application APIs into the test execution context, creating a potential surface for indirect prompt injection if the target application's API returns untrusted or malicious content.
  • Ingestion points: Data is ingested through API responses in SKILL.md (e.g., the getProjectIdByName function parsing JSON from /api/internal/workspaces/...).
  • Boundary markers: The skill does not provide specific delimiters or instructions to the agent to treat data from the target application as untrusted.
  • Capability inventory: The skill guides the creation of scripts with browser automation (Playwright), network request (APIRequestContext), and local filesystem access (for storing storageState).
  • Sanitization: The code includes encodeURIComponent for outgoing request parameters, but lacks validation or sanitization for the data received in API response bodies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:09 AM
Security Audit — agent-trust-hub — playwright-test-data-isolation