e2e-generate

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected This skill appears coherent and consistent with its stated purpose (scaffolding Playwright E2E tests). I found no indicators of deliberate exfiltration, backdoors, or obfuscated malicious code in the provided content. The primary security concern is supply-chain: it recommends installing and running third-party packages (npm install / npx playwright install) and creates persistent caches shared across skills. Those are normal for this workflow but present an inherent supply-chain risk. No hardcoded secrets or suspicious remote endpoints were observed. LLM verification: Functionally benign for its declared purpose — scaffolding Playwright E2E tests and templates — but contains standard supply-chain and operational risks: unpinned npm installs, npx-driven binary downloads without checksums, file writes into the repo, and a shared cache that could leak or be poisoned. No direct evidence of credential exfiltration, hard-coded secrets, reverse shells, or suspicious outbound connections to uncommon domains. Recommendations: require explicit user consent before any i

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/manastalukdar%2Fclaude-devstudio%2Fe2e-generate%2F@51d0c1bea7e953dd00f41e272d3e118b9417620a