playwright-skill

Warn

Audited by Socket on Jun 24, 2026

1 alert found:

Anomaly
AnomalyLOW
src/inject.ts

This module is primarily a Playwright automation helper that performs non-trivial, privacy-invasive instrumentation by monkey-patching console, fetch, and XMLHttpRequest in a live browser session and recording outputs into window global variables without redaction. While it does not itself show exfiltration or overt malware behaviors in this fragment, the injected capability could capture secrets (e.g., tokens logged to console, URLs/parameters) and therefore warrants review of downstream handling, storage, and transmission of window.__capturedConsole/__capturedRequests.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Jun 24, 2026, 12:55 AM
Package URL
pkg:socket/skills-sh/willmarple%2Fvue-conf-26-slides%2Fplaywright-skill%2F@10aa3be3ae351c8856b1a07f420829e1296992e8b458db8f43bf94ef31911d9f
Security Audit — socket — playwright-skill