skills/samhvw8/dotfiles/playwriter/Gen Agent Trust Hub

playwriter

Pass

Audited by Gen Agent Trust Hub on Feb 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the agent to execute shell commands using the playwriter CLI to initialize sessions, manage browser state, and run JavaScript snippets. It also relies on a dynamic instruction set fetched via the playwriter skill command.\n- [EXTERNAL_DOWNLOADS]: The documentation instructs the agent to use npx playwriter@latest or bunx playwriter@latest, which downloads and executes a package from the public NPM registry. This package is maintained by the skill author and serves as a vendor resource.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted data from external websites. Ingestion points: Web page HTML retrieved via getCleanHTML and accessibility trees retrieved via accessibilitySnapshot. Boundary markers: None specified in the provided instructions. Capability inventory: The agent can execute local shell commands and evaluate JavaScript in a stateful sandbox. Sanitization: No sanitization, filtering, or escaping of ingested web content is mentioned in the skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 26, 2026, 11:16 PM