open-gstack-browser

Warn

Audited by Socket on Jun 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned as a headed browser launcher, but its footprint is broader than advertised: it can alter project instructions, run setup/migration commands, and commit repo changes. Install trust is mixed—better than typical curl|bash due to official Bun source and checksum pinning, but the core browser tooling still comes from repo-local scripts/binaries published under a personal account. Overall this is not confirmed malware, but it is a medium-risk skill with disproportionate maintenance and automation capabilities for a simple browser-opening helper.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 14, 2026, 08:51 AM
Package URL
pkg:socket/skills-sh/charlieviettq%2Fawesome-agent-skill%2Fopen-gstack-browser%2F@63d359d191a26461cbf0245d8273d985f1d587409360e0c9a9f19adac7d140ca
Security Audit — socket — open-gstack-browser