task-workflow

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Security
SecurityMEDIUM
assets/scripts/playwright-lifecycle.mjs

This module is a powerful lifecycle/orchestration runner rather than a stealth malware implant. It does not show clear signs of credential theft or hidden payload behavior, but it substantially increases security exposure because it executes caller-provided command strings using bash -lc (arbitrary command execution capability) and performs HTTP fetches to a caller-provided readiness URL. It also persists stdout/stderr to logs, which can leak secrets emitted by executed commands. Overall: likely legitimate for trusted CI usage, but high risk if inputs are not fully controlled.

Confidence: 66%Severity: 72%
Audit Metadata
Analyzed At
Jul 9, 2026, 05:02 PM
Package URL
pkg:socket/skills-sh/customware-ai%2Fskills%2Ftask-workflow%2F@fa025eebd77d7d423b023d155ec1e7e49662fba533d70c35da910f8830b79116
Security Audit — socket — task-workflow