pair-agent

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core pairing behavior is coherent with the stated purpose, and the Bun/ngrok references look consistent with official tooling, but the skill intentionally grants another agent remote browser control, can escalate to cookies/storage/JS access, and includes a much broader gstack preamble than needed for pairing. This looks more like a high-risk remote access skill than malware, with the main concern being powerful browser delegation and external tunnel exposure rather than hidden credential theft.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 11, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fpair-agent%2F@174e6fe0d3cff8922defcdb085ea32d0ee6d2fe3