browse

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities mostly align: this is a browser QA skill, and its browsing, screenshot, form, and state-inspection features are proportionate. The main concern is install/execution trust: the skill requires opaque local gstack binaries and a local setup path that could not be publicly verified from the supplied evidence, plus an official but unpinned Bun `curl|bash` installer. No clear credential-harvesting endpoint or deceptive data routing is shown, so this is better classified as suspicious/high-risk rather than malicious.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 16, 2026, 08:00 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fbrowse%2F@6bdaf1151b7d7699165c7192a455d9a1c0b8196e