playwright-skill

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the Playwright library and its required browser binaries (Chromium) from official, well-known sources using standard package managers.
  • [COMMAND_EXECUTION]: Instructions guide the agent to generate JavaScript automation scripts and execute them locally using the Node.js runtime. These scripts are used for testing localhost or target web applications.
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from web pages (such as page titles, text content, and console logs). This represents an indirect prompt injection surface as the agent may process instructions embedded in the target website's content. However, this is an inherent characteristic of browser automation tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 02:03 AM
Security Audit — agent-trust-hub — playwright-skill