@gitkraken/gk
gk is GitKraken on the command line. It makes working across multiple repos easier with Workspaces, provides access to pull requests and issues from multiple services (GitHub, GitLab, Bitbucket, etc.), and seamlessly connects with GitKraken Client and Git
Findings (1)
- MED
INSTALL_SCRIPTS— @gitkraken/gk runs npm install scripts (preinstall/postinstall). Install scripts execute arbitrary code at install time — a common supply-chain vector.
Embed this badge
[](https://vulnrable.com/mcp/gitkraken--gk/)
Automated registry-metadata scan; not a code audit. Findings come from npm metadata
published by the package owner and from public security advisories (OSV/GHSA) — not from our own
assessment of the code.
Grade scanned 2026-09-14 · package count resolved 2026-08-18.
A package fixed after that date will still show its earlier grade here.
Maintainer and think this is wrong or out of date? Get in touch — corrections are welcome.