playwright-cli
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's core browser automation capabilities mostly match its stated purpose, and there is no direct evidence of credential theft or attacker-controlled exfiltration. Risk comes from broad execution scope (`playwright-cli:*`), arbitrary code execution (`eval`/`run-code`), authenticated storage manipulation, untrusted web-content handling, and the undocumented transitive `install-skills` command.
Confidence: 83%Severity: 68%
Audit Metadata