Back to skill

Security audit

Skill Playwright Html Pdf Renderer Migrate2

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, coherent PDF-rendering helper, with disclosed setup risks around mutable Playwright installation and an under-explained optional cloud browser note.

Install in a minimally privileged or disposable environment, pin Playwright and commit/use a lockfile if possible, and only configure a cloud browser provider if you intentionally want HTML content rendered by that external service.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Playwright Dependency Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9–10
Vulnerability Type: Unpinned third-party dependency and remotely retrieved browser component
Risk Level: Medium

Complete Code Snippet

markdown
- `npm install playwright`
- `npx playwright install chromium`

Technical Analysis

The setup instructions install Playwright without specifying an audited version or enforcing a lockfile. Consequently, npm install playwright resolves whatever package version and transitive dependency graph the configured npm registry serves at installation time.

The subsequent npx playwright install chromium command executes the installed Playwright CLI and downloads a Chromium artifact. Neither an expected version nor an integrity-verification procedure is documented. The effective components can therefore change after the skill has been reviewed.

This is a supply-chain weakness rather than evidence that the current Playwright package is malicious. Exploitation requires compromise or manipulation of a package release, transitive dependency, registry response, local npm configuration, or browser distribution artifact.

Attack Path

  1. An attacker compromises a relevant Playwright release, transitive dependency, npm distribution path, configured registry, or Chromium artifact source.
  2. A user follows the documented setup instructions.
  3. npm install playwright resolves and installs mutable third-party code without a project-enforced version or lockfile.
  4. npx playwright install chromium executes the installed CLI and retrieves an external browser artifact.
  5. Compromised installation code, lifecycle behavior, CLI code, or browser content executes under the installing user's account.

Impact Assessment

Successful exploitation could provide code execution with the privileges of the user performing installation. The resulting access could include project files and other files readable or writable by that account, environment vari ...[truncated 352 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin Playwright to a reviewed exact version rather than resolving the latest release:
    bash
    npm install --save-exact playwright@<reviewed-version>
    
  2. Commit the generated lockfile and use npm ci so installations reproduce the reviewed dependency graph.
  3. Enforce lockfile integrity in CI and reject unexpected lockfile modifications.
  4. Configure an approved npm registry and consider an internal dependency proxy that scans and retains reviewed artifacts.
  5. Pin the associated browser revision through the selected Playwright release and document the expected download source.
  6. Verify downloaded browser artifacts through trusted checksums or signatures where the distribution process supports them.
  7. Perform dependency and provenance checks before upgrades, and test upgrades in an isolated environment.
  8. Run installation with a minimally privileged account or disposable container, without unrelated credentials or sensitive host mounts.
  9. Avoid permitting untrusted project-level or user-level npm configuration to redirect package or browser downloads.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description explicitly scopes the skill to rendering PDFs using local Playwright/Chromium. The API keys section adds support for a cloud browser provider, which implies remote/external service use that is not justified by the stated local-only purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.