canary

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core browsing and screenshot behavior matches canary monitoring, but the surrounding gstack framework adds unrelated repo modification, telemetry, and memory-sync capabilities that are not proportionate to a read-only post-deploy monitor. Install provenance is partially legitimate same-org tooling, so this is not confirmed malware, but the skill’s actual footprint is broader than its stated purpose.

Confidence: 83%Severity: 66%
Audit Metadata
Analyzed At
May 2, 2026, 01:07 AM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fcanary%2F@aa07d3868d9c3b3427154da5072ffe0e022f5c3a