Back to skill

Security audit

Playwright CLI Automation

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Playwright CLI reference skill, with some setup and credential-handling cautions users should apply before following it.

Use this skill only for sites and accounts you are authorized to automate. Install Playwright in a project-local or virtual environment with pinned versions where practical, avoid running install-deps or global installs with admin privileges unless you have reviewed the impact, never hardcode real passwords, and protect auth.json, screenshots, PDFs, and generated scripts as sensitive files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Package and Browser Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–25
Vulnerability Type: Unpinned dependency installation without integrity verification
Risk Level: Medium

Vulnerable code:

bash
npm install -g @playwright/test
# Or
pip install playwright
bash
playwright install
# Install only specific browsers
playwright install chromium firefox
# Install system dependencies on Linux
playwright install-deps

Technical Analysis

The installation instructions retrieve the latest available versions of the Playwright package, browser binaries, and potentially operating-system dependencies at execution time. No exact package version, lockfile, package hash, browser revision validation, or trusted artifact policy is specified.

Consequently, the code reviewed during the audit may differ from the code installed later. A compromised package registry account, malicious future release, registry or repository compromise, or dependency-chain compromise could cause attacker-controlled installation scripts or binaries to execute. The global npm installation also broadens the affected environment, while playwright install-deps can modify system packages and may request elevated privileges depending on the host configuration.

The audit did not identify evidence that the currently named official Playwright packages are malicious. The finding concerns the unsafe, non-reproducible dependency acquisition process.

Attack Path

  1. An attacker compromises an upstream package, maintainer account, transitive dependency, browser artifact distribution channel, or relevant package repository.
  2. The compromised component is published under a version accepted by the unpinned installation commands.
  3. A user or agent follows SKILL.md and runs npm install -g @playwright/test, pip install playwright, or the Playwright browser and system-dependency installation commands.
  4. The package manager download ...[truncated 848 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin npm and Python dependencies to explicitly reviewed versions, for example @playwright/test@<approved-version> and playwright==<approved-version>.
  • Prefer a project-local npm installation with a committed lockfile and npm ci instead of a global installation.
  • For Python, use a locked requirements file that includes cryptographic hashes and install with pip install --require-hashes -r requirements.txt.
  • Pin the Playwright package and associated browser revisions together; do not independently update browser artifacts without review.
  • Download dependencies only from approved registries and repositories, and apply package-manager provenance or signature verification where available.
  • Perform installation in an isolated, non-privileged environment such as a container or dedicated virtual environment.
  • Avoid automatic execution of playwright install-deps. Document the required operating-system packages and versions, review them separately, and require explicit approval before privileged installation.
  • Scan and test dependency updates before promoting them into the trusted execution environment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description is broad enough to match common requests about browsing, screenshots, crawling, or testing, which can cause the skill to activate in contexts the user did not explicitly intend. In a browser automation skill, over-triggering is risky because the capability can perform navigation, recording, and interaction with live web content, increasing the chance of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The examples include sensitive web actions such as login automation, form filling, session reuse, and recording, but the skill does not warn about handling credentials, authenticated sessions, or legal/authorization boundaries. In this context, omission of warnings is dangerous because users may be guided into automating account access or scraping without safeguards, leading to credential exposure, privacy violations, or unauthorized activity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

整个技能说明及示例均以中文呈现,并在示例中使用中文界面标签如“用户名”“密码”“登录”,但没有说明语言限制、适用区域或提供语言选择。根据规则,未获用户选择即固定语言/locale 可能构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.