playwright-bdd-gherkin-syntax
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill guides the agent in managing Gherkin feature files, creating a surface for potential indirect prompt injection if those files contain malicious instructions.
- Ingestion points: The skill instructions imply reading and processing Gherkin .feature files from the project workspace using tools like Read, Glob, and Grep.
- Boundary markers: There are no instructions or patterns provided to isolate or identify untrusted Gherkin content from trusted instructions.
- Capability inventory: The skill metadata and documentation (SKILL.md) describe the use of Bash for test execution and Write/Edit for file modification, which could be abused if an injected instruction is followed.
- Sanitization: No sanitization, validation, or escaping logic is defined for the content extracted from or written to the .feature files.
- [COMMAND_EXECUTION]: The documentation includes standard CLI commands for executing and filtering Playwright tests using the command line.
- Evidence: The skill (SKILL.md) provides several bash examples, such as
npx playwright test --grep @smoke, for test execution and management.
Audit Metadata