stack-ai
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is coherent in purpose and uses an official npm-distributed Membrane CLI, so this is not overtly malicious. However, it is a Stack AI skill that requires a separate Membrane account and routes API access through Membrane's proxy rather than directly to Stack AI, creating third-party data-flow and trust expansion that is only partly reflected in the description.
Confidence: 84%Severity: 52%
Audit Metadata