playwright-browser-automation

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Security
SecurityMEDIUM
skill-report.json

No clear evidence of covert exfiltration, persistence, or explicit malware behavior is demonstrated in the provided fragment. However, the package’s design is materially risky: it can execute dynamically supplied local JavaScript (require(tempFile)) and can automatically install/run dependencies via synchronous npm/npx commands (execSync), both under the user’s privileges. Combined with weakened Chromium sandboxing and generation of screenshot artifacts, this makes the tool dangerous in automated/agent-driven or untrusted-input scenarios. Treat as high supply-chain/execution risk and require strict user approval and input control (especially around generated scripts and any dependency installation).

Confidence: 66%Severity: 83%
Audit Metadata
Analyzed At
Jul 20, 2026, 02:24 AM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fplaywright-browser-automation%2F@d55277f2ad4ac3ee835c3a9c6685a75d7245af2fae370d23e7cc3171e80008b6
Security Audit — socket — playwright-browser-automation