on511-route-monitor

Warn

Audited by Socket on Feb 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Installation of third-party script detected Based on the provided SKILL/instructions, this is a focused web-scraping skill that uses Playwright to collect route-specific public traffic and road-condition data from Ontario 511, Waze, and traffic-tile endpoints and write a local JSON report. The declared capabilities match the required permissions (browser automation, network access, filesystem write). No evidence of credential harvesting, obfuscated payloads, third-party intermediary data exfiltration, or malicious instructions appears in the provided fragment. The primary supply-chain caution is the normal Playwright/browser binary install step — a legitimate dependency but a download-execute step that operators should perform from official sources. Overall the skill appears benign but has moderate operational risk due to network access and dependency installation. LLM verification: This skill appears functionally consistent with its stated purpose (a repeatable route scraper using Playwright). No direct malicious behaviors (credential harvesting, exfiltration, obfuscated payloads, or hidden backdoors) are present in the provided documentation. However, the documented download-execute pattern (npx playwright install / browser binaries) and use of temporary cache paths increases supply-chain risk. Treat installation of Playwright and downloaded browser binaries as a medium-r

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 22, 2026, 09:49 AM
Package URL
pkg:socket/skills-sh/regexboi%2Fskillz%2Fon511-route-monitor%2F@a4e5e0ae5e1d6ef817b2e5fbf9615ad3519b4ac1