stackstate
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally coherent for a Membrane-published connector, and its CLI install path looks ordinary, but the actual integration is not a direct StackState integration. Authentication, credentials, and StackState data are routed through Membrane, a third-party intermediary that becomes a central trust point. That makes this higher risk than a direct official API skill, though there is not enough evidence here to call it malicious.
Confidence: 81%Severity: 58%
Audit Metadata