replit-playwright-chromium

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/browser_monitor.py

No classic malware indicators (e.g., code execution, credential theft, persistence, or reverse shell) are present in this fragment. However, the core functionality is a browser screenshot streamer: it captures live page content via CDP and transmits both URL metadata and raw JPEG screenshots to any client that can reach a WebSocket server bound on 0.0.0.0, with no authentication or access controls. This creates a high privacy/security exposure consistent with surveillance/exfiltration tooling if shipped or deployed unintentionally or exposed on a network.

Confidence: 67%Severity: 78%
Audit Metadata
Analyzed At
Sep 3, 2026, 04:03 PM
Package URL
pkg:socket/skills-sh/skynight137%2Fskills%2Freplit-playwright-chromium%2F@1481315741ae3c76c1c556e3ab3c82fa2da5857b4d363aa61536dd9aef28b968
Security Audit — socket — replit-playwright-chromium