playwright

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the main Playwright guidance is coherent and mostly benign, but the MCP integration weakens trust by recommending an unpinned third-party package while describing official Microsoft MCP tools. No clear credential theft or exfiltration is present, yet browser automation plus third-party MCP execution and real-world action capability create meaningful security risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/phuetz%2Fcode-buddy%2Fplaywright%2F@40d092d09f764e72d69ecb179febcbcf67c47231