ai21-labs

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose, and the CLI install path appears official and npm-based. However, all AI21 access and authentication are routed through Membrane as an intermediary, so credentials and data do not flow directly to AI21. That intermediary model is disclosed and likely intended, which keeps this from malicious classification, but it materially raises trust and data-flow risk compared with a direct AI21 integration.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 28, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fai21-labs%2F@2455c4101c57f3173c0cf8c8763dc138781c2563
Security Audit — socket — ai21-labs