playwright

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The reviewed Playwright automation skill is functionally coherent and consistent with its stated purpose. No explicit embedded malware, obfuscated payloads, or remote exfiltration code appears in the provided documentation. However, the module exposes sensitive, dual-use capabilities: stealth anti-detection features, automated Cloudflare-challenge handling, and persistent storage of authentication cookies. These increase the potential for misuse (scraping protected content, automating account actions, bypassing protections). Operational safeguards are recommended: secure cookie storage (restrict permissions), do not run untrusted scripts with access to secrets, audit/limit stealth and bypass features where misuse is a concern, and enforce network/isolation controls for execution environments.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:09 PM
Package URL
pkg:socket/skills-sh/tianqiye%2Ftockstalk-bot%2Fplaywright%2F@5e243c321e6a7236a9add12022d0bb01975006e1