setup-gbrain
Audited by Socket on Sep 30, 2026
2 alerts found:
Anomalyx2The fragment appears to be legitimate setup documentation for gbrain and does not show clear malicious behavior. It handles sensitive credentials and performs network administration by design. The broad Supabase PAT scope, persistence of the MCP token in local configuration, arbitrary remote MCP trust, and the migration command's URL-in-argv handling warrant security review and hardening, but they are not sufficient evidence of malware.
The fragment is setup documentation for an intentional local transcript-ingestion feature, not demonstrable malware. It introduces a meaningful privacy and data-retention risk because transcripts and local artifacts may contain sensitive information and can be imported, synchronized across Macs, and retained in git history. The referenced scripts must be reviewed to verify scope enforcement, secret scanning, sync behavior, and file handling before enabling the workflow.