dotnet-playwright
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Instructions describe the use of the Playwright installation script and CLI for managing browser binaries. These components are standard tools for the Playwright automation framework and are used for routine environment setup.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates automated browsing of external content, which creates a surface for indirect prompt injection. If an agent processes untrusted data from navigated pages, it could be influenced by embedded instructions.
- Ingestion points: Navigating to external URLs via Page.GotoAsync and interacting with DOM elements in code examples in SKILL.md.
- Boundary markers: None specified in the provided code templates.
- Capability inventory: Includes the ability to perform network operations, automate browser actions, and write trace logs to the file system.
- Sanitization: No explicit sanitization or validation of page content is documented in the examples.
Audit Metadata