playwright-bdd-gherkin-syntax

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill guides the agent in managing Gherkin feature files, creating a surface for potential indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: The skill instructions imply reading and processing Gherkin .feature files from the project workspace using tools like Read, Glob, and Grep.
  • Boundary markers: There are no instructions or patterns provided to isolate or identify untrusted Gherkin content from trusted instructions.
  • Capability inventory: The skill metadata and documentation (SKILL.md) describe the use of Bash for test execution and Write/Edit for file modification, which could be abused if an injected instruction is followed.
  • Sanitization: No sanitization, validation, or escaping logic is defined for the content extracted from or written to the .feature files.
  • [COMMAND_EXECUTION]: The documentation includes standard CLI commands for executing and filtering Playwright tests using the command line.
  • Evidence: The skill (SKILL.md) provides several bash examples, such as npx playwright test --grep @smoke, for test execution and management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:14 AM
Security Audit — agent-trust-hub — playwright-bdd-gherkin-syntax