playwright-skill

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
run.js

No direct malware behavior (e.g., hardcoded credentials, overt exfiltration, backdoor logic) is evident in the provided snippet. However, the module is inherently high-risk because it functions as a universal JavaScript executor: it ingests runtime-supplied code from argv or stdin, writes it to disk, and executes it with require() (full RCE within the current process). It also expands supply-chain exposure by running npm and npx Playwright installation commands at runtime when Playwright is absent. This should only be used with fully trusted inputs in a controlled environment.

Confidence: 80%Severity: 86%
Audit Metadata
Analyzed At
May 10, 2026, 03:17 AM
Package URL
pkg:socket/skills-sh/acaprino%2Falfio-claude-plugins%2Fplaywright-skill%2F@50b81e3b3b0368936b7305aef4c2c907aca8e5fb