setup-gbrain

Warn

Audited by Socket on Sep 30, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
sections/brain-init.md

The fragment appears to be legitimate setup documentation for gbrain and does not show clear malicious behavior. It handles sensitive credentials and performs network administration by design. The broad Supabase PAT scope, persistence of the MCP token in local configuration, arbitrary remote MCP trust, and the migration command's URL-in-argv handling warrant security review and hardening, but they are not sufficient evidence of malware.

Confidence: 96%Severity: 56%
AnomalyLOW
sections/transcript-gate.md

The fragment is setup documentation for an intentional local transcript-ingestion feature, not demonstrable malware. It introduces a meaningful privacy and data-retention risk because transcripts and local artifacts may contain sensitive information and can be imported, synchronized across Macs, and retained in git history. The referenced scripts must be reviewed to verify scope enforcement, secret scanning, sync behavior, and file handling before enabling the workflow.

Confidence: 93%Severity: 58%
Audit Metadata
Analyzed At
Sep 30, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fsetup-gbrain%2F@aff3e0b8e169daf92a5e6e74bb0dbdbf8c4364cd8f6b8d15feaed77309f74934
Security Audit — socket — setup-gbrain