playwright

Fail

Audited by Snyk on Mar 21, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill's examples and workflows show embedding plaintext credentials directly into CLI commands (e.g., fill e2 "password123"), which implies the agent may need to emit user-supplied secrets verbatim in generated commands and outputs, creating an exfiltration risk.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's core workflow and examples in SKILL.md and references (e.g., commands like "$PWCLI" open https://playwright.dev and pwcli open <url>, pwcli eval "el => el.textContent" e12, and data-extraction workflows) instruct the agent to open arbitrary public URLs and read/act on page DOM/content, meaning it fetches untrusted third-party web content that can influence subsequent clicks/eval/actions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The wrapper script (scripts/playwright_cli.sh) invokes "npx --yes --package @playwright/cli playwright-cli", which at runtime fetches the @playwright/cli package from the npm registry and executes remote code that the skill relies on, so the npm fetch is a required runtime external dependency that executes code.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
HIGH
Analyzed
Mar 21, 2026, 07:18 AM
Issues
3
Security Audit — snyk — playwright