browser-matrix-runner

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content and configuration snippets for Playwright, a well-known and trusted end-to-end testing framework.
  • [EXTERNAL_DOWNLOADS]: The instructions include commands to install browser binaries using npx playwright install. These downloads originate from official Microsoft/Playwright infrastructure, which is a well-known and trusted service.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow for analyzing test failure symptoms. If an agent uses these templates to process data originating from an external website being tested (e.g., error messages or DOM content appearing in the 'Symptom' field), there is a theoretical surface for indirect prompt injection. However, this is inherent to the task of processing external data and the skill does not exhibit dangerous autonomous capabilities associated with this risk.
  • Ingestion points: Step 5 processes test failure symptoms which may contain data from the application under test (SKILL.md).
  • Boundary markers: None explicitly defined in the output template.
  • Capability inventory: The skill provides instructions for configuration and manual/CI execution; it does not define autonomous tool-calling loops.
  • Sanitization: None described for the analysis report phase.
  • [COMMAND_EXECUTION]: The skill provides standard shell commands for testing workflows (e.g., npx playwright test). These are transparent, non-obfuscated, and consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:52 AM
Security Audit — agent-trust-hub — browser-matrix-runner