playwright-explore-website
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to navigate to and explore external websites using the Playwright MCP server, which introduces a surface for indirect prompt injection if a web page contains malicious or adversarial instructions.
- Ingestion points: Content is ingested from external, user-specified or discovered website URLs into the agent's context (
SKILL.md). - Boundary markers: Absent. The instructions do not define delimiters or explicit warnings for the agent to ignore instructions embedded within the target website's text.
- Capability inventory: The agent is empowered to discover, document, and interact with 3-5 core features or user flows on the target site (
SKILL.md). - Sanitization: Absent. No text filtering or content sanitization mechanisms are outlined prior to processing website data.
Audit Metadata