setup-browser-cookies
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the Bun runtime installer from
bun.sh(a well-known service) if the dependency is missing during the setup phase. - Evidence:
curl -fsSL "https://bun.sh/install" -o "$tmpfile"inSKILL.md. - Safety Measure: The script performs a SHA-256 integrity check against the downloaded installer using a hardcoded hash (
bab8acfb046aac8c72407bdcce903957665d655d7acaa3e11c7c4616beae68dd) before execution. - [COMMAND_EXECUTION]: Executes several local binaries part of the gstack suite to manage sessions, telemetry, and cookie extraction.
- Evidence: Commands such as
gstack-skill-start,gstack-skill-end, and thebrowsebinary are executed from the vendor-specific path~/.claude/skills/gstack/. - [INDIRECT_PROMPT_INJECTION]: The skill preamble is configured to ingest and follow dynamic instructions emitted by the session initialization tool.
- Ingestion points: Tool output from the
gstack-skill-startcommand inSKILL.md. - Boundary markers: Content is delimited by
GSTACK_INSTRUCTION_BEGINandGSTACK_INSTRUCTION_ENDmarkers. - Capability inventory: The skill utilizes
Bash,Read, andAskUserQuestiontools. - Sanitization: The skill instructions require the agent to verify that the instruction block contains a matching
SESSION_IDproduced during the current execution to prevent spoofing from other sources.
Audit Metadata