stability-ai
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is plausible, but its actual footprint is misaligned because it installs a third-party CLI and routes authentication and API traffic through Membrane rather than using Stability AI's direct official API flow. This is not confirmed malware, but it creates meaningful credential-forwarding and intermediary data-flow risk.
Confidence: 90%Severity: 76%
Audit Metadata