open-gstack-browser
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the bun installation script from the well-known service bun.sh if the runtime is missing. The script is verified against a hardcoded SHA256 checksum (bab8acfb...) before being executed via bash.
- [COMMAND_EXECUTION]: Executes several vendor-provided scripts and binaries (gstack-skill-start, gstack-learnings-log, gstack-skill-end, and browse) located in the ~/.claude/skills/gstack/ directory. It also manages the browser process by reading PIDs from a local state file and using the kill command to terminate stale instances.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and execute instruction blocks (GSTACK_INSTRUCTION_BEGIN) that are emitted by its own startup script at runtime.
- Ingestion points: The standard output of the gstack-skill-start command.
- Boundary markers: The skill uses specific delimiters (GSTACK_INSTRUCTION_BEGIN/END) and requires a matching SESSION_ID to validate instructions.
- Capability inventory: The agent has access to Bash, Read, and AskUserQuestion tools while processing these instructions.
- Sanitization: Instructions are only honored if they appear in the direct tool result of the specific vendor script with a matching session identifier.
Audit Metadata