Skip to content
Back to skills

Setup

ASecurity

Verify the playwright plugin's runtime prerequisites: the playwright-cli binary and a resolvable browser for this machine. Use when: 'set up playwright', 'configure playwright', 'is playwright working', 'install playwright-cli', a browser flow reports the CLI is missing, or before a first E2E run. Actions: check (read-only verification, default) | apply (resolve what check found; apply install-cli performs the global CLI install). Re-runnable and safe.

  • 13 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 2, 2026
ai-agentsshellbashgit

Works with

  • claude code
  • cli

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 2 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add melodic-software/claude-code-plugins --skill setup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Setup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Setup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/melodic-software-setup-04fd4462/badge)](https://www.skillsdirectory.com/skills/melodic-software-setup-04fd4462)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
description: "Verify the playwright plugin's runtime prerequisites: the playwright-cli binary and a resolvable browser for this machine. Use when: 'set up playwright', 'configure playwright', 'is playwright working', 'install playwright-cli', a browser flow reports the CLI is missing, or before a first E2E run. Actions: check (read-only verification, default) | apply (resolve what check found; apply install-cli performs the global CLI install). Re-runnable and safe."
argument-hint: "[check|apply] [install-cli]"
user-invocable: true
disable-model-invocation: true
shell: bash
---

## Pre-computed context

`check`'s `playwright-cli` probe ran at load time. Read this row instead of re-issuing it; it shows
the tool's path when present, or `absent` when missing:

- `playwright-cli`: !`{ command -v playwright-cli 2>/dev/null || echo "absent"; }`

A row reading `[shell command execution disabled by policy]` carries no result: run that tool's
`command -v` probe via Bash instead.

## Purpose

Thin check-centric setup per the uniform setup contract (`docs/plugin-philosophy.md`
"Setup is explicit and repeatable" in the marketplace repository): `check` inspects and
reports, `apply` resolves. This plugin owns no consumer-project configuration and no
`userConfig`. It recommends `@playwright/cli`'s own defaults, so the only tunable
prerequisite is the CLI binary itself. `apply` is guidance-and-verify with exactly one
write path: the explicitly invoked `apply install-cli` global npm install described
below.

Action routing: no argument or `check` runs the check; `apply` runs the check first, then
offers the resolution for each finding; `apply install-cli` additionally authorizes the global
CLI install. All are non-interactive. Never prompt when the action is given.

## `check` (read-only)

The main skill and its reference files are the single source of truth for what the CLI
requires: `${CLAUDE_PLUGIN_ROOT}/skills/playwright/SKILL.md` (Prerequisite + quick start) and
`${CLAUDE_PLUGIN_ROOT}/skills/playwright/reference/` (`commands.md`, `windows-quirks.md`).

**Read it first.** Probe what it actually does, don't recite this file. Then read the
pre-computed `playwright-cli` row, run the remaining probes via Bash, and report a PASS/FAIL/INFO
table with one remediation line per FAIL. Do not modify anything.

1. **`playwright-cli` binary**. The pre-computed `playwright-cli` row (the binary name the skill
   drives; the npm package is `@playwright/cli`). FAIL if absent. Remediation is `apply install-cli`
   below. When present, report the version (`playwright-cli --version`).
2. **Browser availability**. The CLI needs a browser beyond its own install. Per the plugin's
   own `skills/playwright/reference/windows-quirks.md`, local sessions on Windows/macOS/Linux auto-detect system
   Chrome, while a sandboxed/cloud session must run `playwright-cli install-browser` and that
   download can be egress-blocked. INFO: state whether a system browser is resolvable on this
   host and, when it is not, surface the `playwright-cli install-browser` step and the
   sandbox-egress caveat from that reference. Do not assert a browser requirement the shipped
   docs do not; read them and report what they say.
3. **Artifact directory**. INFO: artifacts land in `.playwright-cli/` relative to the working
   directory; note whether it is gitignored in the current project (the skill recommends
   adding it). No write. Reporting only.

## `apply` (idempotent)

Run `check`, then for each FAIL offer the resolution. `apply install-cli` is the one write
path. State the change before running it:

- **CLI absent**. `apply install-cli` runs `npm install -g @playwright/cli`. This is a
  **global install that mutates the user's machine** (the global npm prefix), stated before it
  runs; without the `install-cli` argument, `apply` only prints this command for the user to
  run. After the install, re-run `command -v playwright-cli` and report the actual result.
  Never claim success on npm's exit code alone.
- **browser not resolvable**. Point at `playwright-cli install-browser` per the plugin's
  reference, and note the sandbox-egress caveat when relevant. Guidance only. This skill does
  not provision browsers.
- **`.playwright-cli/` not gitignored**. Suggest adding it to the project `.gitignore`;
  guidance only, no edit.

The vendored-baseline update flow (`/playwright:playwright update`) is **not** this skill's
job. Point at it, do not wrap it. Re-running `apply` when everything already passes changes
nothing and reports "already configured".

## What this skill does NOT do

- Write the plugin cache, Claude Code user settings, or `pluginConfigs`. Nor project files. The
  one explicitly invoked `apply install-cli` global npm install is the only write it performs.
- Provision browsers, run E2E flows, or take screenshots. That is `/playwright:playwright`.
- Run or wrap the maintainer update flow (`/playwright:playwright update`).

Files in this skill

  • SKILL.md4.4 KB
  • evals/evals.json5.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…