gstack
Audited by Socket on Jun 28, 2026
61 alerts found:
Securityx12Anomalyx49SUSPICIOUS: the core retrospective functionality is legitimate and mostly coherent with local git/history analysis, and the gstack helper tooling appears same-publisher rather than a random third party. However, the skill’s shared preamble is over-scoped for a retro, adding optional networked telemetry/artifact sync, persistent tracking, and project-modifying workflows like CLAUDE.md injection and git commits. This looks more like an overreaching platform skill than malware, but its actual footprint is materially broader than its stated purpose.
SUSPICIOUS. The core Codex integration is same-org and purpose-aligned, so this is not malware and not a fake installer lure. However, the skill’s actual footprint is much broader than a simple Codex wrapper: it executes many unverified local gstack helper scripts, uses `source`/`eval`, adds telemetry/artifact-sync flows, and can send substantial repository/plan content to an external AI service. The risk is driven by scope expansion and execution trust, not by confirmed malicious behavior.
SUSPICIOUS. The skill is broadly aligned with its stated purpose and uses same-publisher tooling, so it is not fundamentally malicious. However, it has a large operational footprint, installs from GitHub/Bun rather than a registry, handles multiple sensitive credentials, stores MCP auth in local config, and can sync artifacts/transcripts off-machine. This is a high-trust setup skill with meaningful security exposure, but the behavior is mostly coherent with onboarding gbrain rather than clear credential theft.
SUSPICIOUS. The core design-review behavior is plausible for gstack and the dependency provenance looks same-org, but the skill’s actual footprint is much broader than its stated purpose: telemetry, artifact sync, local HTTP serving, context harvesting, CLAUDE.md routing injection, vendoring migration, and optional commits. This looks more like a general gstack control plane wrapped around a design-review skill than a narrowly scoped review tool.
SUSPICIOUS. The core QA, browser testing, bug fixing, and regression-test behavior is broadly aligned with the stated purpose, but the skill is overextended: it includes extensive telemetry, artifact-sync, local state management, and helper-binary execution beyond what a focused QA skill strictly needs. Same-org evidence for gstack and official bun.sh sourcing lowers malware concern, yet the large helper-binary footprint and partially opaque telemetry/data flows keep security risk at a medium level.
SUSPICIOUS: the skill is not clearly malicious, and its helper binaries appear to come from the same gstack publisher, but its actual footprint is much larger than 'plan review.' It performs configuration management, repo mutation, telemetry/artifact-sync setup, and transitive skill execution, which are disproportionate to the stated purpose and create medium security risk.
SUSPICIOUS. The core design-brainstorming behavior is plausible, but this skill's actual footprint is much broader than its stated purpose: it executes a large gstack runtime framework, uses custom local binaries for core functions, and includes telemetry, artifacts sync, CLAUDE.md routing injection, and git-modifying branches unrelated to generating design variants. I do not see confirmed credential theft or clearly malicious exfiltration, so this is not malware, but the scope and execution trust are disproportionate for a design exploration skill.
SUSPICIOUS. The core tuning/profile behavior is coherent, and the helper binaries appear to be same-org gstack components, which argues against malware. But the skill is overgrown for its stated purpose: it bundles telemetry, artifact sync, CLAUDE.md routing injection, git commits, gbrain integration, and many background shell actions, creating medium security risk even if most flows are opt-in or same-ecosystem.
SUSPICIOUS: the core DX-audit purpose is real, but the actual footprint is much broader than necessary. Same-org gstack tooling reduces outright malware concern, yet the skill bundles extensive shell execution, optional remote telemetry/artifact sync, and repo-modifying side workflows that are only partially related to auditing developer experience.
SUSPICIOUS: the core ship capabilities are coherent with the stated purpose, and the GitHub/GitLab flows look legitimate. Risk comes from the large same-org helper-script trust boundary, optional telemetry/artifact sync, and the skill’s ability to autonomously mutate git state and publish PRs; this looks like a powerful but plausible workflow skill, not confirmed malware.
SUSPICIOUS. The core QA behavior is plausible, but the actual footprint is much broader than 'report-only' testing: it runs a large control plane of local binaries, can modify repo/config state, and may upload telemetry or artifacts. Install trust is partially supported by same-org evidence, so this is not confirmed malware, but the scope and data flows are disproportionate to the stated purpose.
SUSPICIOUS. The core design-consultation purpose is plausible, but the skill's actual footprint is much broader: it performs telemetry, artifact sync, project routing injection, config mutation, and possible git commits unrelated to producing a design system. The data flows appear mostly tied to the gstack ecosystem rather than obvious credential theft, so this is not confirmed malware, but the scope and side effects are disproportionate to the stated purpose.
SUSPICIOUS. The main workflow is coherent with creating a reusable scrape skill, and the referenced tooling appears same-org and documented. However, the actual footprint is disproportionate: it bundles broad gstack session management, analytics, artifact sync, repo modification, and helper-binary execution that go well beyond the stated purpose. This looks more like an expansive platform wrapper than a narrowly scoped skill, creating medium security risk without clear evidence of outright malware.
SUSPICIOUS. The main browser-pairing capability is plausible and the Bun/ngrok sources are mostly official, but the skill's actual footprint is much broader than its stated purpose: it runs many unverifiable local gstack binaries, performs telemetry/artifact-sync actions, can modify project files, and exposes browser access over ngrok. This looks more like an expansive gstack platform skill than a narrowly scoped pairing helper, so the install and execution trust model is only partially aligned with the declared purpose.
SUSPICIOUS. The core health-check behavior is legitimate, but the skill is overloaded with unrelated gstack platform behaviors: telemetry, artifact sync, persistent profiling, CLAUDE.md routing injection, and git-changing migration flows. The large external binary footprint and optional outbound data flows are not well proportioned to a code-quality dashboard.
SUSPICIOUS. The core browsing capability matches the stated QA purpose, and the setup sources are largely same-org or official. But the skill’s footprint is wider than a browser helper: it includes telemetry, artifact sync, config mutation, CLAUDE.md routing injection, and git commits through opaque local binaries, which raises medium trust and scope concerns even without clear malicious intent.
SUSPICIOUS. The core canary-monitoring behavior is plausible, but this skill bundles a large unrelated control plane: telemetry, artifacts sync, project file edits, git commits, and opaque helper binaries. That makes the skill's real footprint disproportionate to 'post-deploy canary monitoring' even though there is not enough evidence here to call it confirmed malware.
SUSPICIOUS. The core browser-launch behavior is plausible, but this skill is over-scoped: it bundles telemetry, artifact sync, repo mutation, routing-rule injection, and git commits that do not cleanly belong in a browser opener. I do not see confirmed malware, but the capability footprint and reliance on opaque local binaries make it a medium-to-high security risk.
This module is primarily a UI/controller for a local extension back-end: it streams activity and inspector results via SSE, polls memory via fetch, renders them into the DOM (generally with an escapeHtml helper), and triggers actions on the server. The biggest supply-chain/security concern is the explicit “PTY/terminal injection” pipeline (window.gstackInjectToTerminal / gstackScanForPTYInject) and a cleanup prompt that instructs using $B eval—meaning this code can cause upstream command execution in an automation/terminal context. Additionally, it sends a pagehide beacon containing sessionId/authToken to a local endpoint. No direct eval/obfuscation/malicious domain contacting is evident in this fragment, but the injection capability makes the overall risk moderate-high if message content or server endpoints are ever attacker-influenced.
SUSPICIOUS. The core doc-audit behavior is legitimate, and helper binaries appear to come from the same gstack publisher, but the skill is over-scoped for a documentation updater: it performs session tracking, telemetry/artifact sync, routing injection, and optional commits/migration flows. This looks more like a benign but invasive meta-skill than malware; risk comes from broad side effects and delegated trust in local gstack binaries, not from clear credential theft or covert exfiltration.
SUSPICIOUS. The advertised diagram function is plausible and the rendering path is mostly local/offline, but the actual footprint is much broader: it executes many local helper binaries, reads project/context state, may alter repo files and commits, and can route telemetry/artifact-sync through gstack tooling. Same-org evidence keeps this below malicious, yet the scope is disproportionate to a simple diagram skill.
SUSPICIOUS. The core queue-report behavior is plausible, and its main dependencies appear same-org and legitimate, but the skill's actual footprint is far wider than its stated read-only purpose. The shared preamble adds telemetry, artifact sync, config prompting, possible file edits, browser opens, and even git commits, which is disproportionate for a 'landing report' dashboard even if much of it is optional or same-org.
SUSPICIOUS: the main browser-QA capability is legitimate and mostly aligned, but the skill’s footprint is broader than its stated purpose. Official Bun install evidence reduces supply-chain concern, yet opaque helper binaries, optional telemetry/artifact sync, cookie handling, repo edits/commits, and transitive invocation of many other skills create medium security risk.
SUSPICIOUS. The core deploy-detection behavior is benign and the external tooling appears to come from the same publisher, but this skill's actual footprint is much broader than its stated purpose. It performs unrelated telemetry, artifact-sync, routing, migration, and persistent state operations through opaque helper binaries, making scope and data flows disproportionate for a deployment-setup helper.
SUSPICIOUS: the core learnings features are plausible, and the helper tooling appears same-org rather than a random third party, but the skill's real footprint is far broader than its stated purpose. Telemetry, artifact sync, routing injection, git commits, and setup/migration actions are disproportionate to a learnings manager and create medium security risk even without clear evidence of malware.
SUSPICIOUS: the core iOS design-review behavior is legitimate and same-publisher tooling appears real, but the skill’s actual footprint is much broader than its stated purpose. The large gstack preamble adds telemetry, artifact sync, local state harvesting, and possible repo mutations/commits that are not necessary for a visual audit, creating medium risk despite no clear evidence of outright malware.
SUSPICIOUS. The core iOS-clean capability is legitimate, and the referenced gstack helpers appear same-org and official, which lowers outright supply-chain concern. But this specific skill carries a much broader gstack control plane: telemetry, artifact sync, context mining, optional remote flows, unrelated CLAUDE.md/git changes, and execution of many local helper binaries. That footprint is disproportionate to a simple DebugBridge removal skill, so the overall classification is suspicious rather than benign.
SUSPICIOUS. The main restore behavior is coherent and largely local, and the helper binaries appear same-org rather than obviously malicious. But the skill inherits a much broader gstack preamble that can change config, edit/commit repo files, perform git sync, and send telemetry/artifact data, which is disproportionate for a context-restore skill and weakens data-flow integrity.
SUSPICIOUS. The core iOS bug-fix behavior is plausible, but this skill bundles a much larger gstack control plane: local helper execution, telemetry, artifacts sync, routing injection, and autonomous real-device actions. The same-org provenance reduces malware confidence, yet the scope and trust footprint are broader than necessary for an iOS bug fixer, making it a medium-high security risk.
SUSPICIOUS: the core iOS regeneration behavior is benign and same-org, but this skill is over-scoped. It mixes unrelated gstack product management, telemetry, artifact sync, CLAUDE.md routing injection, and git automation into a narrowly described iOS bridge sync task, creating medium security risk without clear evidence of malware.
SUSPICIOUS. The core benchmarking behavior is plausible, and the only explicit installer shown is from an official Bun source with checksum verification. But the skill's actual footprint is much broader than performance testing: it can modify project files, commit changes, manage upgrades, log telemetry, and participate in artifact sync. That overreach and partially opaque outbound binaries make it medium risk, though not confirmed malware.
SUSPICIOUS. The core PDF capability is plausible, but this skill bundles a large gstack control plane around it: telemetry, artifact sync, routing injection, git commits, config mutation, and repo guidance. The installer trust appears same-org rather than obviously malicious, but the skill’s actual scope is disproportionate to its narrow stated purpose.
SUSPICIOUS. The core benchmark function is coherent and mostly routes data to expected model providers using same-org tooling, so this is not confirmed malware. But the skill's actual footprint is broader than its stated purpose: it reads credential-related files, runs multiple bundled binaries, writes analytics/state, and the shared preamble can modify repo/config artifacts unrelated to benchmarking. Overall this looks like a legitimate but over-scoped skill framework with medium security risk.
SUSPICIOUS: the core cookie-import behavior is purpose-aligned and uses same-project tooling, but the skill's actual footprint is much broader than its stated purpose. The oversized gstack preamble introduces telemetry, repo modification, artifacts sync, and other side effects that are disproportionate for a cookie setup skill, creating medium security risk without clear evidence of malware.
No direct signs of classical Swift runtime malware (e.g., dynamic code execution, dlopen/dlsym, method swizzling, or explicit process spawning) are present in this fragment. However, the module is security-sensitive: it exposes authenticated state mutation/restore over a local TCP server, can return screenshot data as base64 (/screenshot), and—critically—logs the bootstrap token in clear text (os.log with .public) while also storing it in a predictable temp-file path. Because behavior is driven by injectable closures/resolvers (ElementsBridge/ScreenshotBridge/MutationBridge and registered handlers), a compromised dependency or wiring could repurpose this server to exfiltrate sensitive data or perform unintended actions. Overall this warrants review/hardening, especially around token secrecy and the screenshot/data exposure endpoints.
This DEBUG-only Swift UIKit bridge provides high-risk primitives for abuse: (1) screenshot capture of the active window, (2) recursive extraction of UI/accessibility metadata that can include sensitive user-visible text, and (3) synthetic input injection that can tap and type into the app’s live UI based on externally supplied JSON commands. While this file contains no direct networking/process/persistence or clear obfuscation, the overall security impact is significant if upstream gating/transport permissions are weak. Review and restrict command access and ensure resolver outputs are never exposed outside trusted development contexts.
No direct malware indicators (no exfiltration, credential theft, persistence, or network activity) are evident in the provided fragment. However, the code implements high-impact synthetic touch/input injection by using private UIKit internals and dynamically loaded IOKit HID event creation. The main supply-chain/security concern is misuse risk: if this API is accidentally included in production or exposed to untrusted callers, it could be used for UI automation/redress-style interaction spoofing. Treat as sensitive automation capability and ensure strict build-time/runtime gating and access control beyond what this single file demonstrates.
This module primarily performs structured JSON validation, bounded deduplication, and local append-only logging. It does not directly show malware behaviors such as credential theft, network exfiltration, or destructive operations. However, it contains a significant supply-chain/injection risk: it uses eval on the output of a local helper script to derive runtime variables (affecting the filesystem write path and potentially enabling command execution if helper output is compromised or influenced). It also spawns an asynchronous derivation script whose behavior is not visible here, increasing overall risk surface. Review and harden the eval usage and verify the integrity and output constraints of the helper scripts involved.
This code behaves primarily as a local auditing/telemetry hook: it parses AskUserQuestion events from stdin, extracts question identifiers and user selections (including optional free-text), and forwards structured payloads to a local helper binary while logging errors to disk. No classic malware indicators are present in this fragment, but the module forwards potentially sensitive user/session content to another process via spawnSync and uses stdin-provided cwd to influence the helper’s execution context. Because the helper binary’s behavior is not included here, the overall risk is moderate, driven by privacy/data-handling and delegation rather than overt malicious actions.
No strong indicators of intentional malware in this fragment (no reverse shell, no obfuscation, no external exfiltration logic). The primary security concern is misuse risk: unauthenticated clients can write arbitrary JSON to disk via /api/feedback and can read and serve any existing file within the allowedDir via /api/reload (within-directory information disclosure and content manipulation). Additionally, the module logs full request bodies and automatically spawns a browser-opening command on startup. If this server can be reached by untrusted parties, it warrants a security review and likely hardening (authentication, payload limits, stricter reload allowlist, and log redaction).
This code is an intentional Playwright stealth/fingerprinting evasion module. It injects scripts that override and forge automation-detection-relevant browser APIs (navigator.webdriver, WebGL getParameter, navigator.plugins, window.chrome shims, mediaDevices enumeration) and removes automation marker properties ('cdc_*'). No direct malware behaviors (exfiltration, credential theft, remote execution) are evident in the provided fragment, but the primary security concern is enabling deceptive automated browsing that can violate site policies or facilitate abuse. Further risk depends on how the package is used (targets, authentication flows, and consent).
This code generates a bash preamble that performs session setup and local analytics/telemetry. The major security issue is dynamic shell execution: it `source`s the output of gstack-repo-mode and `eval`s the output of gstack-slug, which could lead to arbitrary command execution if those helpers (or their outputs) are compromised. Additionally, conditional telemetry/logging may create a privacy/exfiltration channel depending on the helper implementations, though direct network exfiltration is not visible in this fragment. Overall: suspicious behavior mainly due to `source <(...)` and `eval` usage.
No overt malicious behavior is evident in the provided module, but it is security-sensitive because it executes a local TypeScript script via Bun using a path that can be influenced by caller-provided options and filesystem probing, and it kills a process based on a persisted on-disk PID record without cryptographic integrity checks. The main supply-chain/runtime risk depends on whether upstream callers or attackers can control opts.scriptPath/metaDir/execPath-derived discovery or tamper with the stateDir/agent record file. If inputs and state files are strictly trusted and protected, risk is lower; otherwise it could enable arbitrary local code execution or denial of service.
No direct malicious indicators (e.g., credential theft, exfiltration endpoints, backdoors, or obfuscation) are present in this snippet. However, the module performs a meaningful supply-chain-sensitive action: it can `git pull` remote updates and then execute `./setup -q` from the updated revision, running silently in the background and only limited by throttling and a local lock. The security posture therefore depends heavily on the trustworthiness and integrity of the git remote/transport and the safety of the repository’s `setup` script.
Overall, this appears to be a benign local timeline reader/formatter with no network exfiltration or typical malware behaviors in the provided fragment. The primary supply-chain security concern is the use of eval on the output of an external helper (gstack-slug), which can turn helper compromise or attacker-influenced output into arbitrary code execution. Additionally, silent error suppression and lenient parsing reduce observability if something goes wrong.
No direct indicators of covert malware (e.g., no exfiltration, no obfuscation, no remote payload execution) are present in this snippet. However, it intentionally reuses the user’s real Chrome session state (Default profile and Local State) while enabling CDP—a powerful control interface—against that real data context. This materially increases local attack impact if an attacker can connect to the CDP port or run untrusted code on the same host. Operationally, it also force-terminates Chrome if shutdown fails.
This module is not performing technical exfiltration by itself (no JavaScript/network actions), but it embeds multiple high-risk social-engineering and instruction-injection payloads—including hidden credential-exfiltration instructions and malicious aria-label directives referencing external attacker-controlled domains. Treat the page as hostile content suitable for prompt-injection/credential-theft risk during rendering or automated consumption; review/sanitize untrusted HTML and neutralize or remove embedded external instructions.
No direct indicators of overt malware are present in this fragment (no credential access, cryptomining, reverse shell, or explicit network calls). The dominant supply-chain/security concern is dynamic shell-code execution via eval of gstack-slug output, which could become command execution if the helper is compromised or its output can be influenced. A secondary risk is the asynchronous enqueue step, which may cause off-host sync/exposure depending on gstack-brain-enqueue’s implementation; behavior is not visible here. The overall risk is therefore moderate, primarily due to eval and unreviewed downstream sync behavior.
No direct exfiltration, credential theft, persistence, or overt malware behavior is visible in this fragment. However, the module contains a significant supply-chain execution risk: eval executes dynamically produced shell code from gstack-slug, and the resulting variables determine filesystem write locations and the argument passed to the enqueue helper. Combined with the unknown behavior of the enqueue helper (potentially involving cross-machine sync), this warrants security review of gstack-slug and gstack-brain-enqueue for trust boundaries and injection/path-manipulation protections. Malware likelihood from this snippet alone appears low-to-moderate, but security risk is moderate due to eval and suppressed background behavior.