playwright-skill
What this skill does
Browser automation using Playwright for tasks like testing, scraping, or interaction with web applications.
github/sickn33 - Path Traversal Risk - 43.8k stars
Threat analysis
Skill info
pkg:github/sickn33/agentic-awesome-skills@11c9e67?skill=playwright-skillAssessments (2)
Path Traversal Risk
Path Traversal Risk via local-llm-review
run.js
The `safeUserPath` function attempts to sanitize paths, but it's not foolproof. If an attacker can inject malicious paths, they might be able to escape the intended directory. This could be exploited Installation Dependency
Installation Dependency via local-llm-review
package.json
The skill depends on `playwright` version `^1.57.0`. While this is a legitimate dependency, it's worth noting that the skill may be vulnerable to any security issues in the Playwright library if not kBadge
Add the Anomity scan badge for playwright-skill to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of playwright-skill? Report an issue or request a rescan.




