playwriter
Pass
Audited by Gen Agent Trust Hub on Jun 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use
npx playwriter@latestorbunx playwriter@latest, which downloads and executes the package from the public NPM registry.- [COMMAND_EXECUTION]: Browser management and task automation are performed through the execution of shell commands using theplaywriterCLI.- [REMOTE_CODE_EXECUTION]: The tool uses the-eflag to execute arbitrary JavaScript code snippets within a browser context, providing a mechanism for dynamic code execution.- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes external web content and dynamically retrieves its own instruction set. - Ingestion points: Data from visited web pages and the output of the
playwriter skillcommand. - Boundary markers: There are no explicit markers or instructions to treat external data as untrusted.
- Capability inventory: The skill can execute shell commands and arbitrary JavaScript in a browser environment.
- Sanitization: No sanitization or validation of the ingested external content is mentioned.
Audit Metadata