browse
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Purpose and capabilities mostly align: this is a browser QA skill, and its browsing, screenshot, form, and state-inspection features are proportionate. The main concern is install/execution trust: the skill requires opaque local gstack binaries and a local setup path that could not be publicly verified from the supplied evidence, plus an official but unpinned Bun `curl|bash` installer. No clear credential-harvesting endpoint or deceptive data routing is shown, so this is better classified as suspicious/high-risk rather than malicious.
Confidence: 87%Severity: 78%
Audit Metadata