gstack-workflow-assistant

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose broadly matches planning, QA, and release workflows, but its trust model is weak. The main concern is install and execution of a same-repo setup path and browser executable without a strong release-verification trail, combined with access to authenticated browser cookies and the ability to perform repository actions like shipping and PR creation. No explicit credential exfiltration or malicious endpoint is shown, so this is high security risk rather than confirmed malware.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Mar 15, 2026, 11:11 PM
Package URL
pkg:socket/skills-sh/adisinghstudent%2Fara.so%2Fgstack-workflow-assistant%2F@47f2efa8a4d8c30ff07fd9c4fa3239664d8f98ce