objectstack-pm-dispatch

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and not overtly malicious: its GitHub, git, and review capabilities match a backlog-dispatch PM workflow, and its documented installer appears legitimate. However, it still carries meaningful risk because it installs through a transitive skills CLI, processes untrusted GitHub content while controlling code-writing subagents, and can autonomously perform impactful GitHub actions including opening and potentially merging PRs. No clear credential theft or off-platform exfiltration is evident, so this is better classified as a high-risk automation skill rather than malware.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Sep 3, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/objectstack-ai%2Fobjectstack%2Fobjectstack-pm-dispatch%2F@8f9fd70537aed13dd35406bc0654527b198883cd5644ae1cc6d734c7df18e0d9
Security Audit — socket — objectstack-pm-dispatch