objective

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose of coordinating multi-PR work on GitHub, and gh usage is legitimate. The main concern is proportional trust: it relies on an unresolved erk CLI for core mutations without verifiable publisher/install provenance, so the overall footprint is not fully trustworthy even though no clear credential theft or exfiltration path is shown.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 8, 2026, 03:22 AM
Package URL
pkg:socket/skills-sh/dagster-io%2Ferk%2Fobjective%2F@fcc024618b7a8a496edb99a48ed497ee5486f015