browse

Warn

Audited by Socket on May 12, 2026

4 alerts found:

Securityx2Anomalyx2
SecurityMEDIUM
src/cookie-import-browser.ts
AnomalyLOW
SKILL.md

SUSPICIOUS. The core browser-testing capability matches the stated purpose, and the Bun install path is better than typical curl|bash because it pins and verifies the installer. But the skill’s footprint is broader than simple QA: it runs many opaque same-org helper binaries, logs analytics, supports remote telemetry/artifact sync, and can edit/commit project routing files. This looks more like a bundled gstack platform skill than a narrowly scoped browser helper. Not confirmed malicious, but medium risk due to breadth, hidden helper behavior, and untrusted web-content processing with Bash access.

Confidence: 100%Severity: 60%
AnomalyLOW
test/fixtures/injection-combined.html

This module is not performing technical exfiltration by itself (no JavaScript/network actions), but it embeds multiple high-risk social-engineering and instruction-injection payloads—including hidden credential-exfiltration instructions and malicious aria-label directives referencing external attacker-controlled domains. Treat the page as hostile content suitable for prompt-injection/credential-theft risk during rendering or automated consumption; review/sanitize untrusted HTML and neutralize or remove embedded external instructions.

Confidence: 100%Severity: 60%
SecurityMEDIUM
test/fixtures/injection-social.html
Audit Metadata
Analyzed At
May 12, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fbrowse%2F@29d57c7e22c9b0ade45515eb129666df257e8776