playwright-scraper

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill/documentation is a legitimate, high-capability Playwright scraping guide. It does not contain direct malicious code or indicators of supply-chain download-execute attacks. However, because it instructs how to handle authentication and extract arbitrary page content, it enables high-risk actions if misused or deployed insecurely: credential exposure (via environment variables, logs, or compromised proxies) and data exfiltration are realistic risks. Recommendations: treat credentials with secret managers, avoid printing secrets, restrict proxy/trust boundaries, and document legal/ethical scraping limits. Overall, not malicious by itself but carries moderate security risk depending on implementation and deployment.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 01:32 AM
Package URL
pkg:socket/skills-sh/alphaonedev%2Fopenclaw-graph%2Fplaywright-scraper%2F@842f27fc4b8164f7340377e72d44638502949728