stability-ai

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent, and the CLI install path appears to be an official npm-distributed Membrane tool rather than a random payload. However, the skill is not a direct Stability AI integration: it requires a Membrane account and routes requests and auth through Membrane's proxy/connection layer, which introduces third-party credential and data-flow trust beyond Stability AI's official API. This is more a Membrane-to-Stability bridge than a native Stability AI skill.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstability-ai%2F@267dc4e662cc54d139fb119b367ecadaeb6d9a5d