gstack

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the Bun installation script from the well-known service at https://bun.sh/install.
  • [REMOTE_CODE_EXECUTION]: Executes the downloaded installation script via bash. The skill performs a SHA256 integrity check against a hardcoded checksum (bab8acfb046aac8c72407bdcce903957665d655d7acaa3e11c7c4616beae68dd) before execution to ensure the file has not been tampered with.
  • [COMMAND_EXECUTION]: Invokes several local scripts and binaries (gstack, gstack-config, gstack-team-init) for configuration and browser interaction. It also automates Git operations to manage routing rules in the project's CLAUDE.md file.
  • [DATA_EXFILTRATION]: Includes the cookie-import-browser command, which allows users to transfer active session data from their local browser into the testing environment. The documentation provides a safety warning to only import cookies from trusted environments.
  • [SAFE]: Mitigates indirect prompt injection risks. Data ingestion points include browser commands (text, html, snapshot). The skill mandates the use of boundary markers (--- BEGIN/END UNTRUSTED EXTERNAL CONTENT ---) and explicitly instructs the agent to ignore any embedded tool calls or instructions within these markers. The capability inventory includes shell execution and file system writes, with sanitization handled via explicit instruction constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 08:50 AM
Security Audit — agent-trust-hub — gstack