objectstack-pm-dispatch
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent and not overtly malicious: its GitHub, git, and review capabilities match a backlog-dispatch PM workflow, and its documented installer appears legitimate. However, it still carries meaningful risk because it installs through a transitive skills CLI, processes untrusted GitHub content while controlling code-writing subagents, and can autonomously perform impactful GitHub actions including opening and potentially merging PRs. No clear credential theft or off-platform exfiltration is evident, so this is better classified as a high-risk automation skill rather than malware.
Confidence: 88%Severity: 74%
Audit Metadata