aiia
Audited by Socket on Mar 4, 2026
1 alert found:
SecurityThis is a documentation-only AI skill manifest that instructs an agent/developer to use the official Membrane CLI to interact with Aiia. The capabilities, install instructions, and data flows are coherent with the stated purpose. The main supply-chain/safety consideration is that all requests and credentials are proxied through Membrane, and the user must trust the Membrane CLI package and backend. There are no signs of direct malicious behavior (no secret harvesting from local files, no suspicious domains, no download-and-execute commands). Because the skill enables actions that can have real-world financial effects (payment initiation), operators should require explicit human authorization before performing payment-related actions. Overall risk is low to moderate due to reliance on a third-party CLI and backend (supply-chain/trust consideration) rather than any intrinsic malicious code in the skill documentation.