playwright-debugger
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes external binaries such as
gh,playwright, andnodeusing a secure launcher script (run-artifact-reader.sh) and specialized Python wrappers. These executions are secured by using absolute paths for interpreters, isolating the environment with/usr/bin/env -i, and strictly allowlisting environment variables likeGH_TOKENandPATHto prevent credential or environment injection. - [INDIRECT_PROMPT_INJECTION]: The skill implements multiple layers of technical and procedural safeguards to mitigate indirect prompt injection from test artifacts. This includes recursive credential redaction via
residual_credentials.py, strict JSON schema validation, and caps on input complexity (nodes, depth, and bytes) inread-playwright-artifact.py. Documentation inSKILL.mdalso explicitly defines safety rules for treating report data as untrusted content. - [EXTERNAL_DOWNLOADS]: Fetches test artifacts from GitHub's official API using the
ghcommand-line tool. This operation is restricted to user-confirmed repository slugs and numeric run IDs, and the extraction process incorporates multiple security checks, such as rejecting symlinks and special files, to prevent archive-based attacks. - [DYNAMIC_EXECUTION]: The skill utilizes
ctypesto access atomic POSIX filesystem operations (renameatx_nporrenameat2) for safe directory publication. It also performs dynamic loading of its own bundled validation module usingimportlib.utilwith logic that ensures the module remains within the trusted skill directory.
Audit Metadata