landing-ai

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its functionality, and the CLI install source is reasonably legitimate, but the core design routes authentication and API traffic through Membrane instead of Landing AI directly. That third-party credential and data mediation is a meaningful integrity risk even without clear evidence of malware.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Apr 23, 2026, 07:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flanding-ai%2F@cda655ad4e8785bb1cae15a5bc90d062608dfc98