playwright
Fail
Audited by Snyk on Mar 21, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The skill's examples and workflows show embedding plaintext credentials directly into CLI commands (e.g., fill e2 "password123"), which implies the agent may need to emit user-supplied secrets verbatim in generated commands and outputs, creating an exfiltration risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's core workflow and examples in SKILL.md and references (e.g., commands like
"$PWCLI" open https://playwright.devandpwcli open <url>,pwcli eval "el => el.textContent" e12, and data-extraction workflows) instruct the agent to open arbitrary public URLs and read/act on page DOM/content, meaning it fetches untrusted third-party web content that can influence subsequent clicks/eval/actions.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The wrapper script (scripts/playwright_cli.sh) invokes "npx --yes --package @playwright/cli playwright-cli", which at runtime fetches the @playwright/cli package from the npm registry and executes remote code that the skill relies on, so the npm fetch is a required runtime external dependency that executes code.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata