playwright-test-generator

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external websites (DOM and accessibility snapshots) to generate test code, which presents a surface for indirect prompt injection.
  • Ingestion points: Described in SKILL.md Step 3 (Browser Exploration), where the agent reads page content.
  • Boundary markers: SKILL.md contains a 'Safety: page content is untrusted data' section that explicitly instructs the agent to treat target content as data and never as instructions.
  • Capability inventory: The agent can write files, execute subprocesses (via scripts/run-preflight-target.sh), and perform network operations through a controlled browser environment.
  • Sanitization: The skill requires sanitization of snapshots to remove PII, cookies, and tokens before use.
  • [COMMAND_EXECUTION]: The skill executes system commands, such as curl for preflight URL validation and project-native test runners like npm or pnpm. These executions are performed through hardened wrappers (scripts/run-preflight-target.sh and scripts/run-raw-aria-snapshot.sh) that select specific interpreters, enforce isolated runtime flags, pin DNS snapshots, and verify the integrity and ownership of the curl binary to prevent exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:37 PM
Security Audit — agent-trust-hub — playwright-test-generator