gstack

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
codex/SKILL.md

SUSPICIOUS: the core Codex integration is mostly coherent and uses an official OpenAI install path, so this is not malware-like. However, the skill's footprint is broader than a simple read-only wrapper: it edits local files, may modify the plan file, emits telemetry through gstack helper binaries, and sends repo/plan content to an external model service. The main risks are external data exposure, prompt-injection exposure from untrusted content, and scope creep relative to the stated purpose.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 23, 2026, 04:17 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack-browse%2Fgstack%2F@ffd9ab29b932f6372d7d7746d7a2cddc993b4e75