Skip to content

playwright-cli: install --skills leaves .playwright-cli/ untracked, and traces there can hold credentials #42307

Description

Version

@playwright/cli@0.1.18 (skills generated from playwright-core), macOS 26.2, Node via npx.

Steps to reproduce

mkdir demo && cd demo && git init
npx --yes @playwright/cli@0.1.18 install --skills
git status --porcelain
?? .claude/skills/playwright-cli/
?? .playwright/

…and once anything writes output (a snapshot, a trace), .playwright-cli/ joins them.

What happens

Three directories appear, and nothing is said about any of them:

path written by what it is
.playwright/ initWorkspace() cli.config.json — project config
.claude/skills/playwright-cli/ install --skills the generated skill
.playwright-cli/ cliOutputDir traces (trace/), snapshots, screenshots, PDFs

None is added to .gitignore, and the install output does not mention them.

Why .playwright-cli/ is the one that matters

A trace records network requests with their headers and bodies, plus DOM snapshots of
the pages that produced them. So a trace of an authenticated flow contains the credential —
Authorization headers, session cookies, the login POST body — sitting in the working tree
as an untracked directory that git add -A will happily take.

That is not hypothetical for the CLI specifically: the skill documents state-save and a
credentialed login flow, and it supports secret substitution that deliberately keeps
passwords out of the terminal (fields render as <secret>…</secret>). Tracing that same
flow writes to disk what the substitution existed to protect — and nothing warns about it.

The project already does this elsewhere

create-playwright has _patchGitIgnore(), which appends — idempotently, append-only,
under a # Playwright header:

node_modules/
/test-results/
/playwright-report/
/blob-report/
/playwright/.cache/
/playwright/.auth/

/playwright/.auth/ is there for exactly this reason. So this isn't a new policy, just a
gap: the scaffolder patches .gitignore and the CLI installer doesn't, for a directory with
the same sensitivity.

Suggestion

  1. Have install --skills call the same _patchGitIgnore treatment for .playwright-cli/
    (and .playwright/, if that is the intended posture). Idempotent and append-only is
    already the established shape.
  2. Say a word about the generated skill directory in the install output — committed or not
    are both reasonable, but silence means every project decides it independently, and
    "regenerate rather than edit" makes the choice consequential.

Happy to send a PR for either if the direction is agreeable.

Unrelated small bug, same area

references/tracing.md documents cleanup as:

find .playwright-cli/traces -mtime +7 -delete

but traceDir is path.join(".playwright-cli", "trace") — singular. The documented command
matches nothing, so traces accumulate for anyone who follows it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions