stability-ai

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent as a Stability AI integration, and its CLI comes from an official npm package, so it is not overtly malicious. However, all authentication and API traffic are funneled through Membrane as an intermediary rather than going directly to Stability AI, creating moderate credential/data-flow risk and making the footprint broader than a direct vendor integration.

Confidence: 84%Severity: 53%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:07 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstability-ai%2F@da9acc5ea159669317ee100973212759bdf0eeec
Security Audit — socket — stability-ai