playwright-explore-website

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to navigate to and explore external websites using the Playwright MCP server, which introduces a surface for indirect prompt injection if a web page contains malicious or adversarial instructions.
  • Ingestion points: Content is ingested from external, user-specified or discovered website URLs into the agent's context (SKILL.md).
  • Boundary markers: Absent. The instructions do not define delimiters or explicit warnings for the agent to ignore instructions embedded within the target website's text.
  • Capability inventory: The agent is empowered to discover, document, and interact with 3-5 core features or user flows on the target site (SKILL.md).
  • Sanitization: Absent. No text filtering or content sanitization mechanisms are outlined prior to processing website data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:23 PM
Security Audit — agent-trust-hub — playwright-explore-website