Back to skill

Security audit

Gstack

Security checks for vulnerabilities and agentic risk

Overview

This skill is a powerful QA/browser automation toolkit, but it also handles real browser sessions and self-updates in ways that need careful review before installation.

Install only if you are comfortable giving this skill access to authenticated browser sessions and letting it persist local browser state/logs. Avoid importing production cookies, disable auto-upgrade, review any CLAUDE.md changes before accepting them, and do not run setup/upgrade commands unless you trust the upstream repository and have reviewed the exact code being executed.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:101
Finding

Unverified Remote Code Execution Through Installation and Upgrade Workflows

Content
View full analysis
&& ./setup` 3. If `bun` is not installed: `curl -fsSL https://bun.sh/install | bash` ``` The upgrade workflow additionally retrieves mutable repository content and immediately executes it: ```bash cd "$INSTALL_DIR" STASH_OUTPUT=$(git stash 2>&1) git fetch origin git reset --hard origin/main ./setup ``` For vendored installations: ```bash PARENT=$(dirname "$INSTALL_DIR") TMP_DIR=$(mktemp -d) git clone --depth 1 https://github.com/garrytan/gstack.git "$TMP_DIR/gstack" mv "$INSTALL_DIR" "$INSTALL_DIR.bak" mv "$TMP_DIR/gstack" "$INSTALL_DIR" cd "$INSTALL_DIR" && ./setup rm -rf "$INSTALL_DIR.bak" "$TMP_DIR" ``` ### Technical Analysis The `curl | bash` pattern passes remotely retrieved content directly to a shell. No immutable version, expected digest, or cryptographic signature is verified before execution. Consequently, the effective code can change after the Skill package has been reviewed. The upgrade workflow has the same trust-boundary problem: it resets the installation to the mutable `origin/main` branch or clones the current repository head and then immediately runs `./setup`. The workflow can also be configured to upgrade automatically, removing per-update user review. The referenced `setup` executable is not present in the supplied artifact. Its behavior and privilege requirements therefore could not be audited, even though multiple instructions require its execution. ### Attack Path 1. An attacker compr ...[truncated 1001 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
README.md:108
Finding

Persistent Agent Steering Through Global and Project CLAUDE.md Modification

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
browse/src/server.ts:307
Finding

Sensitive Cookie-Picker APIs Bypass Bearer Authentication

Content
View full analysis
({ name: b.name, aliases: b.aliases, })), }, { port }); } if (pathname === '/cookie-picker/domains' && req.method === 'GET') { const browserName = url.searchParams.get('browser'); if (!browserName) { return errorResponse("Missing 'browser' parameter", 'missing_param', { port }); } const result = listDomains(browserName); return jsonResponse({ browser: result.browser, domains: result.domains, }, { port }); } ``` It also performs cookie decryption and imports credentials into the automated context: ```typescript if (pathname === '/cookie-picker/import' && req.method === 'POST') { let body: any; try { body = await req.json(); } catch { return errorResponse('Invalid JSON body', 'bad_request', { port }); } const { browser, domains } = body; if (!browser) return errorResponse("Missing 'browser' field", 'missing_param', { port }); if (!domains || !Array.isArray ...[truncated 2154 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
browse/src/read-commands.ts:273
Finding

Cookies Command Returns Full Authentication Cookie Values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
browse/src/server.ts:95
Finding

Persistent Browser Logs Store Potentially Sensitive Data Without Explicit Restrictive Permissions

Content
View full analysis
0) { const entries = consoleBuffer.last(Math.min(newConsoleCount, consoleBuffer.length)); const lines = entries.map(e => `[${new Date(e.timestamp).toISOString()}] [${e.level}] ${e.text}` ).join('\n') + '\n'; await Bun.write(CONSOLE_LOG_PATH, (await Bun.file(CONSOLE_LOG_PATH).text().catch(() => '')) + lines); lastConsoleFlushed = consoleBuffer.totalAdded; } // Network buffer const newNetworkCount = networkBuffer.totalAdded - lastNetworkFlushed; if (newNetworkCount > 0) { const entries = networkBuffer.last(Math.min(newNetworkCount, networkBuffer.length)); const lines = entries.map(e => `[${new Date(e.timestamp).toISOString()}] ${e.method} ${e.url} → ${e.status || 'pending'} (${e.duration || '?'}ms, ${e.size || '?'}B)` ).join('\n') + '\n'; await Bun.write(NETWORK_LOG_PATH, (await Bun.file(NETWORK_LOG_PATH).text().catch(() => '')) + lines); lastNetworkFlushed = networkBuffer.totalAdded; } // Dialog buffer const newDialogCount = dialogBuffer.totalAdded - lastDialogFlushed; if (newDialogCount > 0) { const entries = dialogBuffer.last(Math.min(newDialogCount, dialogBuffer.length)); const lines = entries.map(e => `[${new Date(e.timestamp).toISOString()}] [${e.type}] "${e.message}" → ${e.action}${e.response ? ` "${e.response}"` : ''}` ).join('\n') + '\n'; await Bun.write(DIALOG_LOG_PATH, (await Bun.file(DIALOG_LOG_PATH).text().catch(() => '')) + lines); lastDialogFlushed = dialogBuffer.totalAdded; } ``` The storage directory is created without an explicit mode: ``` ...[truncated 2297 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (318)

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Accessing the macOS Keychain to derive keys for decrypting browser cookies is credential-access behavior. Although the doc notes user approval prompts and in-memory handling, the capability can still expose authenticated sessions to the tool, which is highly sensitive in the context of an AI-driven browser agent.

Content

Scanner excerpt · ARCHITECTURE.md (reported line 98)May include surrounding context.

md
Cookies are the most sensitive data gstack handles. The design:

1. **Keychain access requires user approval.** First cookie import per browser triggers a macOS Keychain dialog. The user must click "Allow" or "Always Allow." gstack never silently accesses credentials.

2. **Decryption happens in-process.** Cookie values are decrypted in memory (PBKDF2 + AES-128-CBC), loaded into the Playwright context, and never written to disk in plaintext. The cookie picker UI never displays cookie values — only domain names and counts.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The architecture explicitly includes direct access to the macOS Keychain and Chromium cookie databases to decrypt and import browser cookies. Even with local-only design and user approval, this materially expands the skill from QA automation into credential/session access, creating risk of account takeover or sensitive-session misuse if the agent or local process is abused.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This line confirms continued Keychain access in implementation details. While the use of explicit argument arrays reduces command injection risk, the underlying capability remains sensitive because it enables retrieval of secrets needed to unlock browser-session material.

Content

Scanner excerpt · ARCHITECTURE.md (reported line 110)May include surrounding context.

md
### Shell injection prevention

The browser registry (Comet, Chrome, Arc, Brave, Edge) is hardcoded. Database paths are constructed from known constants, never from user input. Keychain access uses `Bun.spawn()` with explicit argument arrays, not shell string interpolation.

## The ref system

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Documentation for cookie-import-browser.ts states it can decrypt Chromium cookies from real browsers, which can expose live authenticated sessions and sensitive tokens. In an agent skill context, this is especially dangerous because it enables access to accounts outside the narrow QA task boundary without reauthentication.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A '/document-release' capability that reads every doc file and rewrites project documentation is unrelated to headless browser QA and creates a strong avenue for unintended or adversarial repository modification. In agent contexts, broad autonomous write access to README, CONTRIBUTING, CHANGELOG, and architecture docs can be abused to alter audit trails, insert misleading instructions, or hide risky behavior.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_destructive_autonomous_actions': Autonomous destructive filesystem, shell history, or repository actions in AI agent skills [agent_skills]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · CHANGELOG.md (reported line 113)May include surrounding context.

md
-line replies.
- **Greptile escalation detection** — explicit algorithm to detect prior GStack replies on comment threads and auto-escalate to Tier 2.
- **Greptile severity re-ranking** — replies now include `**Suggested re-rank:**` when Greptile miscategorizes issue severity.
- Static validation tests for `TODOS-format.md` references across skills.

### Fixed
- **`.gitignore` append failures silently swallowed** — `ensureStateDir()` bare `catch {}` replaced with ENOENT-only silence; non-ENOENT errors (EACCES, ENOSPC) logged to `.gstack/browse-server.log`.

### Changed
- `TODO.md` deleted — all items merged into `TODOS.md`.
- `/ship` Step 3.75 and `/review` Step 5 now reference reply templates and escalation detection from `greptile-triage.md`.
- `/ship` Step 6 commit ordering includes TODOS.md in the final commit alongside VERSION + CHANGELOG.
- `/ship` Step 8 PR body includes TODOS section.

## 0.3.7 — 2026-03-14

### Added
- **Screenshot element/region clipping** — `scre

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
99% confidence
Finding

The documented ability to extract cookies from real Chromium browsers matches information-stealer behavior because cookies can be used to hijack live authenticated sessions. In the context of an agent skill, this is more dangerous than in a traditional browser utility because the capability can be chained with navigation and automation to impersonate the user on external services.

Content

Scanner excerpt · CHANGELOG.md (reported line 235)May include surrounding context.

md
e QA examples, and revised demo transcript

### Removed
- `CONDUCTOR_PORT` magic offset (`browse_port = CONDUCTOR_PORT - 45600`)
- Port scan range 9400-9409
- Legacy fallback to `~/.claude/skills/gstack/browse/src/server.ts`
- `DEVELOPING_GSTACK.md` (renamed to CONTRIBUTING.md)

## 0.3.1 — 2026-03-12

### Phase 3.5: Browser cookie import

- `cookie-import-browser` command — decrypt and import cookies from real Chromium browsers (Comet, Chrome, Arc, Brave, Edge)
- Interactive cookie picker web UI served from the browse server (dark theme, two-panel layout, domain search, import/remove)
- Direct CLI import with `--domain` flag for non-interactive use
- `/setup-browser-cookies` skill for Claude Code integration
- macOS Keychain access with async 10s timeout (no event loop blocking)
- Per-browser AES key caching (one Keychain prompt per browser per session)
- DB lock fallback: copies locked cookie DB to /tmp for safe reads
- 18 unit tests with encrypted cookie fixtures

## 0.3.0 — 20

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The changelog explicitly documents decrypting and importing cookies from installed Chromium browsers using macOS Keychain-derived secrets. In an agent skill, browser-cookie extraction is highly sensitive because it can expose authenticated sessions and enable account takeover across websites without user passwords.

Content

Scanner excerpt · CHANGELOG.md (reported line 239)May include surrounding context.

md
- Interactive cookie picker web UI served from the browse server (dark theme, two-panel layout, domain search, import/remove)
- Direct CLI import with `--domain` flag for non-interactive use
- `/setup-browser-cookies` skill for Claude Code integration
- macOS Keychain access with async 10s timeout (no event loop blocking)
- Per-browser AES key caching (one Keychain prompt per browser per session)
- DB lock fallback: copies locked cookie DB to /tmp for safe reads
- 18 unit tests with encrypted cookie fixtures

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Using 'git fetch && git reset --hard' as part of upgrade behavior is destructive because it can discard local changes and forcibly rewrite a working tree. In an agent-operated environment, this is especially dangerous since users may not expect a QA skill to perform irreversible repository state changes during installation or updates.

Content

Scanner excerpt · CHANGELOG.md (reported line 283)May include surrounding context.

md
- Cap console/network buffers at 50k entries (ring buffer) instead of growing without bound
- Fix disk flush stopping silently after buffer hits the 50k cap
- Fix `ln -snf` in setup to avoid creating nested symlinks on upgrade
- Use `git fetch && git reset --hard` instead of `git pull` for upgrades (handles force-pushes)
- Simplify install: global-first with optional project copy (replaces submodule approach)
- Restructured README: hero, before/after, demo transcript, troubleshooting section
- Six skills (added `/retro`)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The instruction rm .claude/skills/gstack is a destructive filesystem operation presented inline without safeguards such as verifying the path, warning about consequences, or suggesting a backup. In this skill context, users or agents may execute commands verbatim, so even a narrowly targeted delete can cause loss of a locally installed skill or break active workflows.

Content

Scanner excerpt · CLAUDE.md (reported line 104)May include surrounding context.

md
symlink or a real copy. If it's a symlink to your working directory, be aware that:
- Template changes + `bun run gen:skill-docs` immediately affect all gstack invocations
- Breaking changes to SKILL.md.tmpl files can break concurrent gstack sessions
- During large refactors, remove the symlink (`rm .claude/skills/gstack`) so the
  global install at `~/.claude/skills/gstack/` is used instead

**For plan reviews:** When reviewing plans that modify skill templates or the

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CLAUDE.md (reported line 107)May include surrounding context.

md
- During large refactors, remove the symlink (`rm .claude/skills/gstack`) so the
  global install at `~/.claude/skills/gstack/` is used instead

**For plan reviews:** When reviewing plans that modify skill templates or the
gen-skill-docs pipeline, consider whether the changes should be tested in isolation
before going live (especially if the user is actively using gstack in other windows).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

git reset --hard origin/main is a high-risk destructive command because it forcibly overwrites the working tree and index. In this repository's active-skill deployment workflow, an agent or user following documentation blindly could erase local development changes or deploy the wrong state, making the skill context more dangerous than a passive code comment.

Content

Scanner excerpt · CLAUDE.md (reported line 142)May include surrounding context.

md
The active skill lives at `~/.claude/skills/gstack/`. After making changes:

1. Push your branch
2. Fetch and reset in the skill directory: `cd ~/.claude/skills/gstack && git fetch origin && git reset --hard origin/main`
3. Rebuild: `cd ~/.claude/skills/gstack && bun run build`

Or copy the binary directly: `cp browse/dist/browse ~/.claude/skills/gstack/browse/dist/browse`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 106)May include surrounding context.

bash
# 1. Copy .env.example and add your API key
cp .env.example .env
# Edit .env → set ANTHROPIC_API_KEY=sk-ant-...

# 2. Install deps (if you haven't already)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 107)May include surrounding context.

bash
# 1. Copy .env.example and add your API key
cp .env.example .env
# Edit .env → set ANTHROPIC_API_KEY=sk-ant-...

# 2. Install deps (if you haven't already)
bun install

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 191)May include surrounding context.

bash
# 1. Copy .env.example and add your API key
cp .env.example .env
# Edit .env → set ANTHROPIC_API_KEY=sk-ant-...

# 2. Install deps (if you haven't already)
bun install

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CONTRIBUTING.md (reported line 268)May include surrounding context.

To go back to the stable global install, just remove the symlink:

bash
rm .claude/skills/gstack

Claude Code falls back to ~/.claude/skills/gstack/ automatically.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
86% confidence
Finding

The cookie-import capability is a legitimate QA feature, but it matches information-stealer behavior because it imports decrypted browser cookies from real user browsers into another tool. In this context the feature is not necessarily malware, but it materially increases credential/session theft risk if abused, compromised, or used on sensitive accounts.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

md
ll QA pass in 60 seconds. |
| `/qa` | QA + fix engineer | Test app, find bugs, fix them with atomic commits, re-verify. Before/after health scores and ship-readiness summary. Three tiers: Quick, Standard, Exhaustive. |
| `/qa-only` | QA reporter | Report-only QA testing. Same methodology as /qa but never fixes anything. Use when you want a pure bug report without code changes. |
| `/setup-browser-cookies` | Session manager | Import cookies from your real browser (Comet, Chrome, Arc, Brave, Edge) into the headless session. Test authenticated pages without logging in manually. |
| `/retro` | Engineering manager | Team-aware retro: your deep-dive + per-person praise and growth opportunities for every contributor. |
| `/document-release` | Technical writer | Update README, ARCHITECTURE, CONTRIBUTING, and project docs to match what you just shipped. |

## Demo: one feature, five modes

I start almost every feature in plan mode. I describe what I want to build, then use `/plan-ceo-review` to

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The command rm -rf .claude/skills/gstack/.git is intentionally scoped, but it still encourages destructive deletion in a chained setup command. While not obviously malicious, it can be unsafe in automated or copied contexts and normalizes unrestricted recursive deletion instead of safer repository-handling practices.

Content

Scanner excerpt · README.md (reported line 112)May include surrounding context.

md
### Step 2: Add to your repo so teammates get it (optional)

> Add gstack to this project: run `cp -Rf ~/.claude/skills/gstack .claude/skills/gstack && rm -rf .claude/skills/gstack/.git && cd .claude/skills/gstack && ./setup` then add a "gstack" section to this project's CLAUDE.md that says to use the /browse skill from gstack for all web browsing, never use mcp\_\_claude-in-chrome\_\_\* tools, lists the available skills: /plan-ceo-review, /plan-eng-review, /review, /ship, /browse, /qa, /setup-browser-cookies, /retro, /document-release, and tells Claude that if gstack skills aren't working, run `cd .claude/skills/gstack && ./setup` to build the binary and register skills.

Real files get committed to your repo (not a submodule), so `git clone` just works. The binary and node\_modules are gitignored — teammates just need to run `cd .claude/skills/gstack && ./setup` once to build (or `/browse` handles it automatically on first use).

Chaining Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The setup command chains copy, delete, directory change, and execution in one line. Chaining destructive and executable operations reduces the chance a user notices an unsafe intermediate step and makes recovery harder if an early command acts on the wrong path.

Content

Scanner excerpt · README.md (reported line 112)May include surrounding context.

md
### Step 2: Add to your repo so teammates get it (optional)

> Add gstack to this project: run `cp -Rf ~/.claude/skills/gstack .claude/skills/gstack && rm -rf .claude/skills/gstack/.git && cd .claude/skills/gstack && ./setup` then add a "gstack" section to this project's CLAUDE.md that says to use the /browse skill from gstack for all web browsing, never use mcp\_\_claude-in-chrome\_\_\* tools, lists the available skills: /plan-ceo-review, /plan-eng-review, /review, /ship, /browse, /qa, /setup-browser-cookies, /retro, /document-release, and tells Claude that if gstack skills aren't working, run `cd .claude/skills/gstack && ./setup` to build the binary and register skills.

Real files get committed to your repo (not a submodule), so `git clone` just works. The binary and node\_modules are gitignored — teammates just need to run `cd .claude/skills/gstack && ./setup` once to build (or `/browse` handles it automatically on first use).

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The README recommends curl -fsSL https://bun.sh/install | bash, which executes a remotely fetched script directly in the shell without verification or pinning. If the remote endpoint, transport, or served script is compromised, users could execute arbitrary code on their machine during installation.

Content

Scanner excerpt · README.md (reported line 629)May include surrounding context.

md
Run `/gstack-upgrade` — it updates both the global install and any vendored project copy automatically.

**`bun` not installed?**
Install it: `curl -fsSL https://bun.sh/install | bash`

## Upgrading

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This is another instance of the same global recursive deletion command. The risk remains high because the README encourages direct execution and the skill ecosystem may execute shell instructions with limited human scrutiny.

Content

Scanner excerpt · README.md (reported line 641)May include surrounding context.

md
Paste this into Claude Code:

> Uninstall gstack: remove the skill symlinks by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f ~/.claude/skills/$s; done` then run `rm -rf ~/.claude/skills/gstack` and remove the gstack section from CLAUDE.md. If this project also has gstack at .claude/skills/gstack, remove it by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f .claude/skills/$s; done && rm -rf .claude/skills/gstack` and remove the gstack section from the project CLAUDE.md too.

## Development

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This is another instance of the same global recursive deletion command. The risk remains high because the README encourages direct execution and the skill ecosystem may execute shell instructions with limited human scrutiny.

Content

Scanner excerpt · README.md (reported line 641)May include surrounding context.

md
Paste this into Claude Code:

> Uninstall gstack: remove the skill symlinks by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f ~/.claude/skills/$s; done` then run `rm -rf ~/.claude/skills/gstack` and remove the gstack section from CLAUDE.md. If this project also has gstack at .claude/skills/gstack, remove it by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f .claude/skills/$s; done && rm -rf .claude/skills/gstack` and remove the gstack section from the project CLAUDE.md too.

## Development

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This is another instance of the same global recursive deletion command. The risk remains high because the README encourages direct execution and the skill ecosystem may execute shell instructions with limited human scrutiny.

Content

Scanner excerpt · README.md (reported line 641)May include surrounding context.

md
Paste this into Claude Code:

> Uninstall gstack: remove the skill symlinks by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f ~/.claude/skills/$s; done` then run `rm -rf ~/.claude/skills/gstack` and remove the gstack section from CLAUDE.md. If this project also has gstack at .claude/skills/gstack, remove it by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f .claude/skills/$s; done && rm -rf .claude/skills/gstack` and remove the gstack section from the project CLAUDE.md too.

## Development

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This is another instance of the same global recursive deletion command. The risk remains high because the README encourages direct execution and the skill ecosystem may execute shell instructions with limited human scrutiny.

Content

Scanner excerpt · README.md (reported line 641)May include surrounding context.

md
Paste this into Claude Code:

> Uninstall gstack: remove the skill symlinks by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f ~/.claude/skills/$s; done` then run `rm -rf ~/.claude/skills/gstack` and remove the gstack section from CLAUDE.md. If this project also has gstack at .claude/skills/gstack, remove it by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f .claude/skills/$s; done && rm -rf .claude/skills/gstack` and remove the gstack section from the project CLAUDE.md too.

## Development

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This is another instance of the same global recursive deletion command. The risk remains high because the README encourages direct execution and the skill ecosystem may execute shell instructions with limited human scrutiny.

Content

Scanner excerpt · README.md (reported line 641)May include surrounding context.

md
Paste this into Claude Code:

> Uninstall gstack: remove the skill symlinks by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f ~/.claude/skills/$s; done` then run `rm -rf ~/.claude/skills/gstack` and remove the gstack section from CLAUDE.md. If this project also has gstack at .claude/skills/gstack, remove it by running `for s in browse plan-ceo-review plan-eng-review review ship retro qa qa-only setup-browser-cookies document-release; do rm -f .claude/skills/$s; done && rm -rf .claude/skills/gstack` and remove the gstack section from the project CLAUDE.md too.

## Development

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
browse/test/commands.test.ts:621

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/dev-skill.ts:24

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/skill-check.ts:101

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/helpers/eval-store.ts:523

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/skill-e2e.test.ts:127

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
browse/src/cli.ts:20

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/skill-e2e.test.ts:21

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
browse/src/server.ts:33

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
browse/test/cookie-import-browser.test.ts:8