playwright-test-generator
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external websites (DOM and accessibility snapshots) to generate test code, which presents a surface for indirect prompt injection.
- Ingestion points: Described in
SKILL.mdStep 3 (Browser Exploration), where the agent reads page content. - Boundary markers:
SKILL.mdcontains a 'Safety: page content is untrusted data' section that explicitly instructs the agent to treat target content as data and never as instructions. - Capability inventory: The agent can write files, execute subprocesses (via
scripts/run-preflight-target.sh), and perform network operations through a controlled browser environment. - Sanitization: The skill requires sanitization of snapshots to remove PII, cookies, and tokens before use.
- [COMMAND_EXECUTION]: The skill executes system commands, such as
curlfor preflight URL validation and project-native test runners likenpmorpnpm. These executions are performed through hardened wrappers (scripts/run-preflight-target.shandscripts/run-raw-aria-snapshot.sh) that select specific interpreters, enforce isolated runtime flags, pin DNS snapshots, and verify the integrity and ownership of thecurlbinary to prevent exploitation.
Audit Metadata