Version
@playwright/cli@0.1.18 (skills generated from playwright-core), macOS 26.2, Node via npx.
Steps to reproduce
mkdir demo && cd demo && git init
npx --yes @playwright/cli@0.1.18 install --skills
git status --porcelain
?? .claude/skills/playwright-cli/
?? .playwright/
…and once anything writes output (a snapshot, a trace), .playwright-cli/ joins them.
What happens
Three directories appear, and nothing is said about any of them:
| path |
written by |
what it is |
.playwright/ |
initWorkspace() |
cli.config.json — project config |
.claude/skills/playwright-cli/ |
install --skills |
the generated skill |
.playwright-cli/ |
cliOutputDir |
traces (trace/), snapshots, screenshots, PDFs |
None is added to .gitignore, and the install output does not mention them.
Why .playwright-cli/ is the one that matters
A trace records network requests with their headers and bodies, plus DOM snapshots of
the pages that produced them. So a trace of an authenticated flow contains the credential —
Authorization headers, session cookies, the login POST body — sitting in the working tree
as an untracked directory that git add -A will happily take.
That is not hypothetical for the CLI specifically: the skill documents state-save and a
credentialed login flow, and it supports secret substitution that deliberately keeps
passwords out of the terminal (fields render as <secret>…</secret>). Tracing that same
flow writes to disk what the substitution existed to protect — and nothing warns about it.
The project already does this elsewhere
create-playwright has _patchGitIgnore(), which appends — idempotently, append-only,
under a # Playwright header:
node_modules/
/test-results/
/playwright-report/
/blob-report/
/playwright/.cache/
/playwright/.auth/
/playwright/.auth/ is there for exactly this reason. So this isn't a new policy, just a
gap: the scaffolder patches .gitignore and the CLI installer doesn't, for a directory with
the same sensitivity.
Suggestion
- Have
install --skills call the same _patchGitIgnore treatment for .playwright-cli/
(and .playwright/, if that is the intended posture). Idempotent and append-only is
already the established shape.
- Say a word about the generated skill directory in the install output — committed or not
are both reasonable, but silence means every project decides it independently, and
"regenerate rather than edit" makes the choice consequential.
Happy to send a PR for either if the direction is agreeable.
Unrelated small bug, same area
references/tracing.md documents cleanup as:
find .playwright-cli/traces -mtime +7 -delete
but traceDir is path.join(".playwright-cli", "trace") — singular. The documented command
matches nothing, so traces accumulate for anyone who follows it.
Version
@playwright/cli@0.1.18(skills generated fromplaywright-core), macOS 26.2, Node vianpx.Steps to reproduce
…and once anything writes output (a snapshot, a trace),
.playwright-cli/joins them.What happens
Three directories appear, and nothing is said about any of them:
.playwright/initWorkspace()cli.config.json— project config.claude/skills/playwright-cli/install --skills.playwright-cli/cliOutputDirtrace/), snapshots, screenshots, PDFsNone is added to
.gitignore, and the install output does not mention them.Why
.playwright-cli/is the one that mattersA trace records network requests with their headers and bodies, plus DOM snapshots of
the pages that produced them. So a trace of an authenticated flow contains the credential —
Authorizationheaders, session cookies, the login POST body — sitting in the working treeas an untracked directory that
git add -Awill happily take.That is not hypothetical for the CLI specifically: the skill documents
state-saveand acredentialed login flow, and it supports secret substitution that deliberately keeps
passwords out of the terminal (fields render as
<secret>…</secret>). Tracing that sameflow writes to disk what the substitution existed to protect — and nothing warns about it.
The project already does this elsewhere
create-playwrighthas_patchGitIgnore(), which appends — idempotently, append-only,under a
# Playwrightheader:/playwright/.auth/is there for exactly this reason. So this isn't a new policy, just agap: the scaffolder patches
.gitignoreand the CLI installer doesn't, for a directory withthe same sensitivity.
Suggestion
install --skillscall the same_patchGitIgnoretreatment for.playwright-cli/(and
.playwright/, if that is the intended posture). Idempotent and append-only isalready the established shape.
are both reasonable, but silence means every project decides it independently, and
"regenerate rather than edit" makes the choice consequential.
Happy to send a PR for either if the direction is agreeable.
Unrelated small bug, same area
references/tracing.mddocuments cleanup as:but
traceDirispath.join(".playwright-cli", "trace")— singular. The documented commandmatches nothing, so traces accumulate for anyone who follows it.