webapp-testing

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The package provides legitimate Playwright testing utilities and examples and matches its stated purpose. The primary security concern is operational: scripts/with_server.py accepts and runs arbitrary shell commands and the documentation discourages source review before execution, creating a high-risk sink for command execution and potential data exposure. There is no direct evidence of embedded malware in the provided content, but the design and guidance increase the chance of misuse or supply-chain abuse. Recommended actions: review and harden scripts/with_server.py, require source review, implement command sanitization or restricted modes, and adopt artifact and navigation whitelists before use in untrusted contexts.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:42 PM
Package URL
pkg:socket/skills-sh/warpdotdev%2Foz-skills%2Fwebapp-testing%2F@b742f03a6d17cc18b7c15058acc0779ef0a9ab82