setup-browser-cookies

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the Bun runtime installer from bun.sh (a well-known service) if the dependency is missing during the setup phase.
  • Evidence: curl -fsSL "https://bun.sh/install" -o "$tmpfile" in SKILL.md.
  • Safety Measure: The script performs a SHA-256 integrity check against the downloaded installer using a hardcoded hash (bab8acfb046aac8c72407bdcce903957665d655d7acaa3e11c7c4616beae68dd) before execution.
  • [COMMAND_EXECUTION]: Executes several local binaries part of the gstack suite to manage sessions, telemetry, and cookie extraction.
  • Evidence: Commands such as gstack-skill-start, gstack-skill-end, and the browse binary are executed from the vendor-specific path ~/.claude/skills/gstack/.
  • [INDIRECT_PROMPT_INJECTION]: The skill preamble is configured to ingest and follow dynamic instructions emitted by the session initialization tool.
  • Ingestion points: Tool output from the gstack-skill-start command in SKILL.md.
  • Boundary markers: Content is delimited by GSTACK_INSTRUCTION_BEGIN and GSTACK_INSTRUCTION_END markers.
  • Capability inventory: The skill utilizes Bash, Read, and AskUserQuestion tools.
  • Sanitization: The skill instructions require the agent to verify that the instruction block contains a matching SESSION_ID produced during the current execution to prevent spoofing from other sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — setup-browser-cookies