playwright-scraper-skill

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This package is a dual-use web-scraping utility that intentionally includes anti-bot evasion techniques (navigator.webdriver hiding, addInitScript injection, UA spoofing, human-like delays) and documents plans for proxy rotation and CAPTCHA-solving integrations. The provided file is a README/manifest and contains no direct evidence of embedded malware, hard-coded credentials, or exfiltration endpoints, but the documented capabilities materially increase misuse and privacy/ethical risk. Primary actionable concerns: credential forwarding to CAPTCHA services, unpinned dependencies (supply-chain risk), and the presence of effective evasion techniques that enable bypassing site protections. Operators should audit the actual scripts before use, pin/verify dependencies, and treat deployment as potentially abusive tooling rather than benign utility.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 05:12 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fplaywright-scraper-skill%2F@742f0864625d696aeb851cbf34cdde731dc01f3a