playwright-cli

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Anomaly
AnomalyLOW
references/running-code.md

No definitive malware or explicit exfiltration behavior is shown in the provided fragment. However, the module performs sensitive automation: it hardcodes credentials, executes an authenticated login, persists session/auth state to auth.json, and scrapes DOM text then returns it to the caller. These patterns are commonly used for legitimate testing but are also frequently associated with credential/session harvesting or unauthorized scraping when combined with additional logic not shown here (e.g., uploading auth.json or transmitting scraped data). Treat this as high sensitivity and verify the surrounding package context and downstream handling of auth.json and returned data.

Confidence: 45%Severity: 56%
Audit Metadata
Analyzed At
Aug 6, 2026, 03:16 PM
Package URL
pkg:socket/skills-sh/wso2%2Flabs-agentic-engineer%2Fplaywright-cli%2F@f22505eb59eeaeb7db0441e75125f0e9671426cd7cbc4bd40b3b50e88eb2b9d4
Security Audit — socket — playwright-cli