playwright-skill

Warn

Audited by Socket on Aug 23, 2026

1 alert found:

Security
SecurityMEDIUM
run.js

This file is not a standalone stealer/backdoor; it is a high-privilege universal JavaScript executor. It executes attacker-controlled code in-process via require(tempFile) after writing it to disk, and it can perform runtime 'npm install' and 'npx playwright install chromium' when Playwright is missing. That combination creates substantial security and supply-chain risk in any context where the executed input or runtime environment is not fully trusted. No explicit malicious payload is present in the shown code, but the capability to run arbitrary code is itself a major danger signal.

Confidence: 70%Severity: 85%
Audit Metadata
Analyzed At
Aug 23, 2026, 04:02 AM
Package URL
pkg:socket/skills-sh/thearchitectit%2Fawesome-opencode-skills%2Fplaywright-skill%2F@383f2261e2b96cbb90a4ba43111d25194fbaff47e718a1e98cc6f8a6157d91ed
Security Audit — socket — playwright-skill