AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itprivacy

The viral GStack '/browse' skill is being questioned because it can decrypt browser credentials: why it is not safe to use

Reports say the popular GStack /browse skill can unlock saved browser credentials, raising privacy and security questions for AI agent users.

What happened

A July 8, 2026 report from The Hacker News, citing Sophos telemetry from seven days in June 2026, said some AI coding agents were triggering security detections that usually match attacker behavior. The products named were Claude Code, Cursor, and OpenAI Codex.

The report specifically pointed to the popular third-party GStack skill pack. It said the `/browse` skill used PowerShell, a Windows command tool, and DPAPI, a Windows feature that can unlock data tied to a logged-in account, to access saved browser credential data. Sophos said credential-access activity made up 56.2% of its blocked activity sample. It also observed one case where Claude Code ran with the `--dangerously-skip-permissions` flag while listing Windows credentials.

What it means for you

If you use Claude Code, Codex, or similar tools, this is a reminder that a skill can have broad access to your device, browser, and accounts. For a normal user, any install that asks for browser automation or wide local access should be treated as both a privacy risk and a security risk.

What to do instead

Only install skills you actually need. Read the requested permissions before you approve them. Avoid skills that ask for browser access, saved passwords, or full local file access unless that is essential to the task. Prefer separate browser profiles without saved credentials for agent-driven browsing. Keep important accounts protected with a password manager and multi-factor authentication. If a tool offers a permissions prompt, do not bypass it.

If you want a safer starting point, AgentPod lists only reviewed, tested skills, but you should still check what each skill can access before installing it.

Sources:

  • https://thehackernews.com/2026/07/ai-coding-agents-found-triggering.html?m=1
  • https://github.com/garrytan/gstack/issues/1543

Source: https://thehackernews.com/2026/07/ai-coding-agents-found-triggering.html?m=1

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.