qa-testing-playwright

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation and execution of official testing frameworks and Model Context Protocol (MCP) servers from trusted organizations like Microsoft and Google using npx (e.g., @playwright/mcp, chrome-devtools-mcp, and the Playwright browser binaries). These downloads target well-known, established repositories and registries.
  • [INDIRECT_PROMPT_INJECTION]: As a tool designed for web browser automation and accessibility tree inspection, the skill creates a surface where the agent could ingest adversarial content from external websites.
  • Ingestion points: The agent ingests data from web pages via the Playwright browser interface, accessibility snapshots, and the Chrome DevTools Protocol (SKILL.md, references/playwright-mcp.md).
  • Boundary markers: While the skill documentation encourages structured planning, it does not prescribe specific delimiter-based boundary markers for isolating untrusted web content from the agent's primary instructions.
  • Capability inventory: The skill enables browser navigation, network request handling (APIRequestContext), and file system operations including writing traces, videos, and screenshots across multiple scripts.
  • Sanitization: The instructions rely on Playwright's native handling of the DOM and accessibility tree; no additional sanitization or filtering of external text is defined in the skill logic.
  • [SAFE]: The skill demonstrates safe secret management by instructing users to store credentials in .env files or CI secrets rather than hardcoding them. It also provides explicit warnings about the risks of sharing browser profiles when using automation tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:31 AM
Security Audit — agent-trust-hub — qa-testing-playwright