playwright-skill

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
run.js

This module is primarily a high-risk execution harness: it ingests user-provided JavaScript from argv/file/stdin, writes it to disk, and executes it in-process via require(), yielding an effective arbitrary code execution primitive for anyone who can control the input. It also performs runtime package installation and Playwright browser binary installation via shell commands when Playwright is missing, increasing supply-chain and network exposure in CI/automation environments. No explicit exfiltration/backdoor logic is present in the snippet itself, but the capability for abuse is substantial.

Confidence: 78%Severity: 92%
Audit Metadata
Analyzed At
Jul 28, 2026, 03:14 PM
Package URL
pkg:socket/skills-sh/FixMyBerlin%2Ffixmyskills%2Fplaywright-skill%2F@7ab8053d3a3a6d818d5f3a63e27e45fffc9f95b1c2791085facd066522d09192
Security Audit — socket — playwright-skill