playwright-cli
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capability matches the stated purpose of browser automation, and the source/project appears to be official Microsoft Playwright. However, the install instructions are internally inconsistent: the skill says to install `@playwright/mcp` for a `playwright-cli` binary, while official Playwright CLI docs point to `@playwright/cli`. That mismatch creates medium supply-chain trust risk even though the ecosystem and publisher are legitimate. No clear credential harvesting or malicious exfiltration is present, but the skill is powerful and can act on arbitrary sites with persistent session state.
Confidence: 87%Severity: 58%
Audit Metadata