Back to skill

Security audit

Playwright Cli

Security checks for vulnerabilities and agentic risk

Overview

This browser automation skill is coherent, but it asks users to install mutable global tooling and exposes session, storage, network, code execution, and destructive browser controls without enough safety scoping.

Review this before installing. Use a pinned, reviewed package version if possible, avoid running the install with elevated privileges, and treat browser state files, cookies, localStorage, screenshots, PDFs, traces, videos, and network logs as sensitive. Use these commands only on approved sites and avoid production authenticated sessions unless you have a clear need and a cleanup plan.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Global Dependency and Agent Skill Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented cookie, localStorage, and state save/load operations directly expose and persist authentication and session material, yet the skill provides no warning about credential theft, session hijacking, or cross-context reuse. Because this skill is meant for browser automation and AI-agent use, these commands materially increase the chance that secrets are exported, stored insecurely, or restored into the wrong session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents commands that write screenshots, PDFs, and other browser artifacts to disk, but gives no warning that these outputs can contain sensitive page content, personal data, tokens, or internal documents visible in the browser session. In an AI-agent context, silent persistence to files increases the risk of unintended retention, later disclosure, or inclusion in logs and tool outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill exposes network inspection and browser-context code execution features without warning that they may reveal transmitted secrets or execute unsafe logic against live pages. In an agent-driven workflow, network and run-code are especially risky because they can surface authorization headers, form contents, and page data or perform arbitrary actions within an authenticated session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The session-management section documents destructive commands such as closing all browsers, killing processes, and deleting session data without warning about irreversible loss of browsing state or abrupt termination of active work. In automation environments, these commands can disrupt other sessions, destroy evidence/debug context, or remove persisted data needed for safe recovery and auditing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.