Playwright Interactive

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it asks users to run with full host access without enough security warning or containment.

Install only if you trust the publisher and understand why full host access is needed. Prefer running it in a disposable or tightly controlled workspace, avoid exposing secrets, and look for a documented no-full-access path or explicit warning before using it on important files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This markdown file directs the user to disable sandboxing entirely, which materially affects system integrity and expands the impact of any subsequent actions. While it states this is a temporary requirement, it does not explicitly warn the user about the security consequences of granting full host access.

Scope Creep

Low
Category
Excessive Agency
Content
exercising permissions granted by this License.

      "Source" form shall mean the preferred form for making modifications,
      including but not limited to software source code, documentation
      source, and configuration files.

      "Object" form shall mean any form resulting from mechanical
Confidence
70% confidence
Finding
not limited to

Scope Creep

Low
Category
Excessive Agency
Content
"Object" form shall mean any form resulting from mechanical
      transformation or translation of a Source form, including but
      not limited to compiled object code, generated documentation,
      and conversions to other media types.

      "Work" shall mean the work of authorship, whether in Source or
Confidence
70% confidence
Finding
not limited to

Scope Creep

Low
Category
Excessive Agency
Content
or by an individual or Legal Entity authorized to submit on behalf of
      the copyright owner. For the purposes of this definition, "submitted"
      means any form of electronic, verbal, or written communication sent
      to the Licensor or its representatives, including but not limited to
      communication on electronic mailing lists, source code control systems,
      and issue tracking systems that are managed by, or on behalf of, the
      Licensor for the purpose of discussing and improving the Work, but
Confidence
70% confidence
Finding
not limited to

Scope Creep

Low
Category
Excessive Agency
Content
liable to You for damages, including any direct, indirect, special,
      incidental, or consequential damages of any character arising as a
      result of this License or out of the use or inability to use the
      Work (including but not limited to damages for loss of goodwill,
      work stoppage, computer failure or malfunction, or any and all
      other commercial damages or losses), even if such Contributor
      has been advised of the possibility of such damages.
Confidence
70% confidence
Finding
not limited to

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal