webapp-testing

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The reviewed content documents a Playwright-based local testing toolkit and a helper that starts servers via operator-supplied commands. I found no direct evidence of malware or obfuscated malicious code in the provided fragment. The primary security concerns are: arbitrary command execution via the server helper, potential supply-chain exposure through npm or other lifecycle scripts invoked by those commands, and sensitive-data exposure via saved page content and screenshots. The documentation's recommendation to treat scripts as black boxes and to run them before reading their source is a notable operational risk. Before running helpers on untrusted projects, inspect the helper implementation (avoid shell=True patterns), sandbox server processes, and audit dependency install scripts and any captured artifacts.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 2, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/jg-chalk-io%2FNora-LiveKit%2Fwebapp-testing%2F@580190297b49aa4b2bd632050a4165b327b90e8c