open-gstack-browser

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the bun installation script from the well-known service bun.sh if the runtime is missing. The script is verified against a hardcoded SHA256 checksum (bab8acfb...) before being executed via bash.
  • [COMMAND_EXECUTION]: Executes several vendor-provided scripts and binaries (gstack-skill-start, gstack-learnings-log, gstack-skill-end, and browse) located in the ~/.claude/skills/gstack/ directory. It also manages the browser process by reading PIDs from a local state file and using the kill command to terminate stale instances.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and execute instruction blocks (GSTACK_INSTRUCTION_BEGIN) that are emitted by its own startup script at runtime.
  • Ingestion points: The standard output of the gstack-skill-start command.
  • Boundary markers: The skill uses specific delimiters (GSTACK_INSTRUCTION_BEGIN/END) and requires a matching SESSION_ID to validate instructions.
  • Capability inventory: The agent has access to Bash, Read, and AskUserQuestion tools while processing these instructions.
  • Sanitization: Instructions are only honored if they appear in the direct tool result of the specific vendor script with a matching session identifier.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — open-gstack-browser