shotstack

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the install path is mostly legitimate and same-ecosystem, but the skill is internally inconsistent and routes Shotstack access through Membrane as a third-party intermediary. The main issue is purpose-capability mismatch plus broader-than-necessary data flow, not confirmed malware.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 11, 2026, 05:27 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshotstack%2F@15e1084a47fee5c59a1b32baf4c372ebd2852474