playwright-debugger

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes external binaries such as gh, playwright, and node using a secure launcher script (run-artifact-reader.sh) and specialized Python wrappers. These executions are secured by using absolute paths for interpreters, isolating the environment with /usr/bin/env -i, and strictly allowlisting environment variables like GH_TOKEN and PATH to prevent credential or environment injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements multiple layers of technical and procedural safeguards to mitigate indirect prompt injection from test artifacts. This includes recursive credential redaction via residual_credentials.py, strict JSON schema validation, and caps on input complexity (nodes, depth, and bytes) in read-playwright-artifact.py. Documentation in SKILL.md also explicitly defines safety rules for treating report data as untrusted content.
  • [EXTERNAL_DOWNLOADS]: Fetches test artifacts from GitHub's official API using the gh command-line tool. This operation is restricted to user-confirmed repository slugs and numeric run IDs, and the extraction process incorporates multiple security checks, such as rejecting symlinks and special files, to prevent archive-based attacks.
  • [DYNAMIC_EXECUTION]: The skill utilizes ctypes to access atomic POSIX filesystem operations (renameatx_np or renameat2) for safe directory publication. It also performs dynamic loading of its own bundled validation module using importlib.util with logic that ensures the module remains within the trusted skill directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:38 PM
Security Audit — agent-trust-hub — playwright-debugger